<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Cyber Why: What We Read This Week]]></title><description><![CDATA[Our weekly snarky newsletter focused on technology and cybersecurity.]]></description><link>https://www.thecyberwhy.com/s/what-we-read-this-week</link><image><url>https://substackcdn.com/image/fetch/$s_!7SG5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png</url><title>The Cyber Why: What We Read This Week</title><link>https://www.thecyberwhy.com/s/what-we-read-this-week</link></image><generator>Substack</generator><lastBuildDate>Fri, 01 May 2026 06:25:41 GMT</lastBuildDate><atom:link href="https://www.thecyberwhy.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Tyler Shields]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[thecyberwhy@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[thecyberwhy@substack.com]]></itunes:email><itunes:name><![CDATA[Tyler Shields]]></itunes:name></itunes:owner><itunes:author><![CDATA[Tyler Shields]]></itunes:author><googleplay:owner><![CDATA[thecyberwhy@substack.com]]></googleplay:owner><googleplay:email><![CDATA[thecyberwhy@substack.com]]></googleplay:email><googleplay:author><![CDATA[Tyler Shields]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[THE CYBER WHY: What We Read This Week]]></title><description><![CDATA[Issue #89 &#183; April 07, 2026 &#183; ~9 min read]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-ee0</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-ee0</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Wed, 08 Apr 2026 00:26:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7SG5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>We&#8217;re BACK! Yep that&#8217;s right, after nearly 18 month away we&#8217;ve decided to pick up the pen and get back after it. The cyber world is a completely different place then when you last saw us. AI has taken over the world and cybersecurity is no different. We&#8217;ve been staring at the newsfeed for the last seven days and every single article is about AI. AI agents doing pentesting. AI agents replacing SaaS. AI agents that need their own security stack. Sequoia is telling us the next trillion-dollar company sells work, not tools. Karpathy is telling us engineers are irrelevant to their own workflows. And eleven keynote speakers at RSAC 2026 all agreed on exactly one thing: we need to secure AI agents, all while agreeing on exactly zero ways to actually do it. It&#8217;s giving &#8220;everyone knows the house is on fire but nobody can find the extinguisher&#8221; vibes. We&#8217;re glad to be back and we hope you love the new content - more coming soon!</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SIIN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SIIN!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 424w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 848w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 1272w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SIIN!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif" width="329" height="411.51791530944627" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:384,&quot;width&quot;:307,&quot;resizeWidth&quot;:329,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SIIN!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 424w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 848w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 1272w, https://substackcdn.com/image/fetch/$s_!SIIN!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff0b1c3-71e0-491a-ab14-d4bad04bc6b0_307x384.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Cyber Why! Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h6><strong>[AI + Security]</strong></h6><p><strong><a href="https://pulse.latio.tech/p/ai-code-security-enterprise-governance">AI Code Security: Enterprise Governance for AI Generated Code</a> (Latio)</strong></p><p>James Berthoty over at Latio dropped a killer piece that should be required reading for every CISO trying to figure out what to do about the influx of AI-generated code flooding their repositories. We're watching a brand new security category emerge in real time, AI Code Security, and it's distinct from traditional SAST, DAST, or SCA. The problem isn't that AI writes bad code (though it does). The problem is that AI writes code <em>at scale</em>, <em>without context</em>, and <em>without the institutional memory</em> that a human developer carries about why certain patterns exist in a codebase.</p><p>The governance challenge isn&#8217;t about scanning output. It&#8217;s about understanding intent, provenance, and drift. When a junior dev uses Cursor to generate an authentication module, who owns the security posture of that code? The dev who prompted it? The AI that wrote it? The platform team that approved the model? Traditional AppSec tooling wasn&#8217;t built for this question because the question didn&#8217;t exist eighteen months ago. The companies that figure out AI code governance first (think policy engines that sit between the model and the merge request) are building the next foundational layer of the DevSecOps stack.</p><p>The security industry spent decades learning to secure code humans write. We now have approximately twenty months to figure out how to secure code that nobody wrote.</p><blockquote><p><strong>FOR INVESTORS:</strong> AI Code Security is an (re)emerging category with no clear incumbent. First movers that nail the governance layer (not just scanning) will own the workflow. Watch for Series A/B companies positioning here in 2026.</p></blockquote><div><hr></div><h6><strong>[STARTUP / VC]</strong></h6><p><strong><a href="https://sequoiacap.com/article/services-the-new-software/">Services: The New Software</a> (Sequoia Capital).</strong></p><p>Sequoia put out a thesis piece that should make every cybersecurity SaaS vendor deeply uncomfortable. They believe we&#8217;re moving from &#8220;software as a service&#8221; to &#8220;service as software.&#8221; The next trillion-dollar company won&#8217;t sell you a tool and a dashboard, it&#8217;ll sell you the <em>outcome</em>. Copilots and chat interfaces are simply the transition drug. Agents are the destination. The companies that get there first capture the margin that currently sits with the systems integrators, MSSPs, and consulting firms extracting value from the complexity your tools created in the first place.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RaSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RaSj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 424w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 848w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 1272w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RaSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png" width="1023" height="495" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec354011-23f0-4700-a284-356a096246e3_1023x495.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:495,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RaSj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 424w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 848w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 1272w, https://substackcdn.com/image/fetch/$s_!RaSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec354011-23f0-4700-a284-356a096246e3_1023x495.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image from Sequoia Capital - Go the complete post for details.</figcaption></figure></div><p>Apply this to cybersecurity and the implications are enormous. Think about what an MSSP actually does: they take your SIEM, your EDR, your SOAR, your threat intel feeds, and they provide the <em>human labor</em> to make all of it work together. If an AI agent can do that (triage alerts, investigate incidents, write detection rules, tune policies) then the $30B managed security market isn&#8217;t a services market anymore. It&#8217;s a software market. And the vendors that make that transition eat the services revenue. The ones that don&#8217;t become commoditized infrastructure underneath someone else&#8217;s agent.</p><p>This is the most important strategic piece I&#8217;ve read this quarter. It reframes every vendor evaluation, every competitive analysis, every market sizing model. The question isn&#8217;t &#8220;how big is the EDR market?&#8221; anymore. It&#8217;s &#8220;how much of the SOC analyst&#8217;s job does your product replace end-to-end?&#8221;</p><p><strong>The next war in cybersecurity isn&#8217;t over features. It&#8217;s over which vendors use agents to eliminate the need for services entirely.</strong></p><blockquote><p><strong>FOR INVESTORS:</strong> Incumbents that complete the services-to-software transition will trade at infrastructure multiples. The ones that don&#8217;t become commodity inputs. The gap between those two outcomes is where the alpha lives.</p></blockquote><div><hr></div><h6><strong>[INDUSTRY]</strong></h6><p><strong><a href="https://cisotradecraft.substack.com/p/saas-is-dead-why-your-next-security">SaaS is Dead: Why Your Next Security Tool Should Be a &#8220;Vibe-Coded&#8221; Agent</a> (CISO Tradecraft).</strong></p><p>CISO Tradecraft picked up the Sequoia thread and ran it through the practitioner lens. Their take is that the next generation of security tools won&#8217;t be dashboards you configure, they&#8217;ll be agents you <em>describe</em>. &#8220;Vibe coding&#8221; applied to security operations. You tell the agent what you want (&#8221;monitor my cloud configs for drift against CIS benchmarks and auto-remediate anything below critical&#8221;) and it builds the workflow, executes it, and reports back. No playbook authoring. No integration mapping. No three-month professional services engagement to get value from the thing you already bought.</p><p>The article is a bit off in places, (NO we&#8217;re not twelve months away from fully autonomous SOCs) but the directional argument is right. The SOAR market failed because it required security teams to become software developers to write playbooks. Agentic AI flips that. The security team describes the outcome and the agent figures out the implementation. That&#8217;s a fundamentally different value proposition, and it explains why every major security vendor at RSAC was demoing &#8220;agentic&#8221; capabilities whether they had them or not. </p><p><strong>SOAR failed because it asked security analysts to become developers. Agentic AI succeeds by asking them to just be analysts again.</strong></p><div><hr></div><h6><strong>[INDUSTRY]</strong></h6><p><strong><a href="https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes">I Watched All 11 Main Stage Keynotes at RSAC 2026</a> (Defenders Initiative).</strong></p><p>My good friend Adrian Sanabria did the Lord&#8217;s work and sat through all eleven RSAC 2026 main stage keynotes so the rest of you could go drink at the expo area instead. He found that the industry has reached violent agreement that AI agents need securing, but nobody has a coherent framework for how to do it. Every keynote mentioned &#8220;agentic AI.&#8221; Every vendor had an &#8220;agentic&#8221; demo. And the actual substance behind most of it ranged from &#8220;we added an LLM to our workflow engine&#8221; to &#8220;we&#8217;re thinking about thinking about agent security.&#8221;</p><p>The useful signal buried in the noise is that identity is the new perimeter for AI agents (who is the agent acting as?), observability is the blind spot (most orgs can&#8217;t see what their AI is doing in production), and the supply chain risk from AI model dependencies makes traditional software supply chain look like a safe little puppy. The conference effectively confirmed that &#8220;AI Agent Security&#8221; is the next major category but we&#8217;re in the &#8220;twenty vendors, zero standards&#8221; phase. Sound familiar? It should. This is cloud security circa 2016. </p><p><strong>Everyone at RSAC agreed AI agents need securing. That&#8217;s the easy part. The hard part is that the agents are already deployed and nobody&#8217;s watching them.</strong></p><div><hr></div><h6><strong>[AI + SECURITY]</strong></h6><p><strong><a href="https://franklyspeaking.substack.com/p/ai-is-breaking-security-categories">AI Is Breaking Security Categories</a> (Frank Wang).</strong></p><p>Frank Wang wrote the piece that every analyst (myself included) needed to read. His thesis is that AI-native security companies don&#8217;t fit into existing market categories, and Gartner&#8217;s Magic Quadrants are going to look increasingly absurd trying to classify them. When a product uses an AI agent to do continuous pentesting, automated remediation, AND compliance reporting, is that a vulnerability management tool? A GRC platform? A pentesting service? The answer is yes, and also no, and also the categories are the wrong question.</p><p>This resonates deeply with what I&#8217;m was seeing as an analyst at Omdia. We&#8217;re building market models for categories that are actively merging and splitting in real time. The AI-native startups aren&#8217;t building &#8220;better SIEM&#8221; or &#8220;better EDR&#8221; they&#8217;re building agents that collapse multiple security functions into a single workflow. That&#8217;s not an incremental improvement. That&#8217;s a category extinction event for vendors who defined themselves by a single Gartner box. Next time a vendor tells you they&#8217;re the &#8220;leader&#8221; in a Gartner category, ask them which category they&#8217;ll be in when that quadrant doesn&#8217;t exist anymore.</p><p><strong>Gartner&#8217;s category taxonomy was built for a world where products did one thing. AI agents do twelve things. The map no longer matches the territory.</strong></p><blockquote><p><strong>FOR INVESTORS:</strong> Category convergence means TAM models based on existing categories are increasingly unreliable. The winners will be companies that own <em>entire process flows</em>, not <em>categories</em>. Diligence needs to shift from &#8220;what category are you in?&#8221; to &#8220;what job are you eliminating?&#8221;</p></blockquote><div><hr></div><h6><strong>[AI + WORKFORCE]</strong></h6><p><strong><a href="https://www.the-ai-corner.com/p/andrej-karpathy-ai-workflow-shift-agentic-era-2026">Andrej Karpathy: The AI Workflow Shift Explained 2026</a> (The AI Corner).</strong></p><p>Karpathy laid out the trajectory that every technical leader needs to internalize, we&#8217;re moving from humans writing code with AI assistance to AI writing code with human oversight. The human role shifts from creator to reviewer, from architect to editor. More importantly, the review bottleneck is already real. When AI can generate code 100x faster than a human can review it, the security implications aren&#8217;t theoretical,  they&#8217;re operational. You cannot manually review AI-generated pull requests at the rate they&#8217;re being created. The math doesn&#8217;t work.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nlub!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nlub!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 424w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 848w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 1272w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nlub!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp" width="515" height="288.4" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:616,&quot;width&quot;:1100,&quot;resizeWidth&quot;:515,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;File:Andrej karpathy 2016.webp - Wikimedia Commons&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="File:Andrej karpathy 2016.webp - Wikimedia Commons" title="File:Andrej karpathy 2016.webp - Wikimedia Commons" srcset="https://substackcdn.com/image/fetch/$s_!Nlub!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 424w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 848w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 1272w, https://substackcdn.com/image/fetch/$s_!Nlub!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6692c6cb-c777-4ec4-bf6b-ec1295260cd8_1100x616.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This connects directly to the Latio piece above. If humans are becoming reviewers rather than authors, then the tooling needs to shift from &#8220;help developers write secure code&#8221; to &#8220;help reviewers verify AI-generated code is secure.&#8221; That&#8217;s a different product. A different workflow. A different buyer. And most AppSec vendors are still building for the old model. Go look at your last five merged PRs. How many were AI-generated? Now ask yourself how long the security review took on each one. If the answer is &#8220;the same as always,&#8221; your review process is already underwater.</p><p><strong>Engineers aren&#8217;t being replaced by AI. They&#8217;re being promoted to AI supervisors. The problem is nobody trained them for the new job.</strong></p><div><hr></div><h6><strong>THE WRAPUP</strong></h6><p>The thread running through every article this week is the same: the AI agent era isn&#8217;t coming, it&#8217;s already here, and the cybersecurity industry is scrambling to figure out the implications in real time. Sequoia says the business model shifts from tools to outcomes. Karpathy says the human role shifts from creator to reviewer. RSAC confirmed the industry agrees this is happening while demonstrating it has no idea what to do about it. And meanwhile, AI-generated code is flooding production repositories faster than anyone can review it, new security categories are emerging and collapsing simultaneously, and the old analyst frameworks for understanding this market are breaking under the weight of products that refuse to fit in a single box. The gap between &#8220;we know this is a problem&#8221; and &#8220;we have a plan&#8221; is the widest I&#8217;ve seen in twenty-five years. That gap is also where every interesting company in 2026 is being built.</p><div><hr></div><p><strong>Also worth your time this week:</strong></p><ul><li><p><strong><a href="https://www.cybrsecmedia.com/the-ai-revolution-could-bring-a-new-kind-of-tyranny-unless-we-force-a-better-outcome/">Katie Moussouris warns of a &#8220;tyranny of optimization&#8221;</a></strong>: The AI revolution doesn&#8217;t just create security problems, it creates governance problems. When algorithms optimize for efficiency at the expense of resilience, we get systems that work perfectly until they don&#8217;t. Worth reading for the policy lens alone.</p></li><li><p><strong><a href="https://nextbigteng.substack.com/p/ai-infrastructure-roadmap-five-frontiers-for-2026">Bessemer maps five frontiers for AI infrastructure in 2026</a></strong>: Reasoning, multimodal, edge, simulation, and trust/safety. The trust and safety frontier is where security and AI infrastructure converge and it&#8217;s the least funded of the five. That tells you something.</p></li></ul><div><hr></div><p>If you've made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share The Cyber Why with your friends. We would love to reach a bigger audience, and referrals are how we do it.</p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (9/3/24)]]></description><link>https://www.thecyberwhy.com/p/09032024tcw</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/09032024tcw</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Wed, 04 Sep 2024 03:45:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After a long weekend of family time, TCW is back at it again with a new drop! </p><p>This week, the TCW team learns about the &#8220;Agentic Economy,&#8221; debates the Telegram CEO&#8217;s arrest, and cries over a city playing the blame game with a researcher. We discuss the issue of cybersecurity delusion and learn one million checkbox lessons in creativity. All this and more in this week&#8217;s The Cyber Why!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong><a href="https://www.thecyberwhy.com/podcast">The Cyber Why POD - Now in 4k!</a> (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong><a href="http://thecyberwhy.com/">TCW Newsletter </a>and the <a href="https://www.thecyberwhy.com/podcast">TCW Podcast</a> both have 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>WOAH - Agent Smith is BACK!</h2><p><strong><a href="https://medium.com/@kyeg/the-agentic-economy-is-coming-ecf789a370f2">The Agentic Economy: How Billions of AI Agents Will Transform Our World</a> (Kyle Gomez)</strong></p><p>We will open this week&#8217;s TCW with a bit of futurism. The article explores the rise of the "Agentic Economy," where autonomous AI agents will handle everything from shopping to complex negotiations on our behalf. These digital minions could transform industries, labor markets, and even our day-to-day lives by making us either incredibly efficient or utterly irrelevant. While the idea of AIs doing our light work sounds appealing, the author also hints at the unsettling possibility of these agents outpacing human control, making decisions that could redefine what it means to work and exist in the economy.</p><p>The future of human work in an "Agentic Economy" looks both promising and unsettling. On one hand, AI agents could free us from mundane tasks and boost productivity, giving us more time for creative or meaningful pursuits. On the other hand, these same agents might outcompete humans in many jobs, leading to potential job displacement and a rethinking of what "work" even means. In short, AI might be our new colleague&#8212;or our biggest competition. I&#8217;d love to hear your thoughts in the comments below!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aVr_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aVr_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aVr_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg" width="438" height="219" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1400,&quot;resizeWidth&quot;:438,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Matrix 4: Agent Smith Could Return - Here's How&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Matrix 4: Agent Smith Could Return - Here's How" title="Matrix 4: Agent Smith Could Return - Here's How" srcset="https://substackcdn.com/image/fetch/$s_!aVr_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aVr_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd96da7e0-d1b8-430d-8aaa-7335b4d763b2_1400x700.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Telegram&#8217;s CEO Is Going To Be Staying In France Longer Than Expected</h2><p><strong><a href="https://www.france24.com/en/europe/20240828-telegram-ceo-durov-to-appear-in-paris-court-after-initial-detention-ends">Telegram CEO Durov placed under formal investigation and banned from leaving France</a> (France24)<br><a href="https://www.forbes.com/sites/mollybohannon/2024/08/28/who-is-pavel-durov-arrested-telegram-ceo-in-the-middle-of-growing-tensions-between-russia-and-france-and-others/">Who Is Pavel Durov? Telegram CEO Charged With Multiple Crimes In France</a> (Forbes) <br><a href="https://www.wired.com/story/telegram-pavel-durov-arrest-investigation-allegations/">Telegram CEO Pavel Durov&#8217;s Arrest Linked to Sweeping Criminal Investigation</a> (WIRED)</strong></p><p><em>(Rick pick)</em> Telegram CEO Pavel Durov is currently under formal investigation in France and facing serious charges related to criminal activities linked to his Telegram platform. French authorities detained him but later released him on &#8364;5 million bail. Forbes estimates he has a net worth of $15.5B, so making bail was trivial. The charges against him include enabling illicit transactions, child pornography, drug trafficking, and money laundering. The arrest has caused quite a stir, upsetting free speech and privacy advocates, while others have said this is politically motivated as Durov is a Russian/French dual citizen. Durov has five different passports. $15.5B buys you many nationalities. I know some folks are upset about this. For me, anything potentially disrupting the crime on the Telegram platform is a win. I recognize it's not all bad, but that place is a cesspool for illegal activities. Tracking the cybercriminal underground shift here over the years has been interesting. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6USv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6USv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 424w, https://substackcdn.com/image/fetch/$s_!6USv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 848w, https://substackcdn.com/image/fetch/$s_!6USv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 1272w, https://substackcdn.com/image/fetch/$s_!6USv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6USv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png" width="400" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:261286,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6USv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 424w, https://substackcdn.com/image/fetch/$s_!6USv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 848w, https://substackcdn.com/image/fetch/$s_!6USv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 1272w, https://substackcdn.com/image/fetch/$s_!6USv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f5eeff-65da-4680-a0ac-9c897d2f08e2_400x576.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Russian &#8220;hacktivist&#8221; group Killnet <a href="https://www.reliaquest.com/blog/killnet-the-hactivist-group-that-started-a-global-cyber-war/">recruiting</a> on Telegram</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Stop Blaming The Researcher - They Aren&#8217;t The Problem</h2><p><strong><a href="https://www.bleepingcomputer.com/news/security/researcher-sued-for-sharing-data-stolen-by-ransomware-with-media/">Researcher sued for sharing data stolen by ransomware with media</a> (Bleeping Computer)<br><a href="https://www.bleepingcomputer.com/news/security/columbus-investigates-whether-data-was-stolen-in-ransomware-attack/">Columbus investigates whether data was stolen in ransomware attack</a> (Bleeping Computer)<br><a href="https://www.nbc4i.com/news/local-news/columbus/city-hack/he-proved-the-columbus-data-leak-hurts-the-public-now-the-city-wants-to-silence-him/">He proved the Columbus data leak hurts the public. Now, the city has silenced him</a> (NBC4i.com)</strong></p><p>The City of Columbus, Ohio, has sued security researcher David Leroy Ross for illegally downloading and sharing data stolen by the Rhysida ransomware gang during a July 2024 attack. The lawsuit claims Ross's actions caused community concern and interfered with police investigations, seeking damages over $25,000 and a restraining order to prevent further dissemination of the stolen data. Ross disputed claims that the leaked data was unusable, revealing sensitive information about individuals, including police officers and crime victims.</p><p>What a waste of city resources! Money and time are spent chasing down someone doing good for the community by helping them stay educated and informed on the risks of the breach. The city argues that the researcher's actions caused serious public inconvenience and alarm, and the researcher claims he&#8217;s simply trying to help. The worst part about this is that the case remains &#8220;ongoing,&#8221; with a pretrial conference scheduled for September 2025! Yes.. a year away. What a clusterf*&amp;#.</p><p>Here&#8217;s a <a href="https://www.nbc4i.com/wp-content/uploads/sites/18/2024/08/Complaint-240829.pdf">link to the court complaint</a>&nbsp;PDF&nbsp;for those who are morbidly interested.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Cybersecurity Is Delusional</h2><p><strong><a href="https://www.resilientcyber.io/p/cybersecuritys-delusion-problem">Cybersecurity's Delusion Problem</a> (Resilient Cyber)</strong></p><p>Cybersecurity lives in a state of constant delusion. We believe that the world revolves around us, and we have a tendency to take an ego-centric view when thinking of the incentive structure of cybersecurity. This thought-provoking article from Chris Hughes at Resilient Cyber sheds light on this and many other intriguing concepts. These cyber earworms have been whispered from the shadows for ages but generally aren&#8217;t called out to be debated in the light of day. Approaching topics such as "cybersecurity not being the center of the universe,&#8221; &#8220;security tools are overhyped,&#8221; and &#8220;cybersecurity is a big echo chamber,&#8221; this article takes aim at an issue we have in our industry concerning misaligned incentives and insufficient consequences. Thanks for writing this piece, Chris. I hope we can get better soon.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/09032024tcw?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/09032024tcw?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>One Million Lessons In Creativity</h2><p><strong><a href="https://x.com/itseieio/status/1829268247105138764">One Million Check Boxes - A Badass Thread </a>(@itseieio)</strong></p><p>This fantastic thread on X details a fascinating story about a website called "One Million Checkboxes" (OMCB), where users can check or uncheck boxes globally. The creator initially worried about hacking but discovered that users&#8212;mainly creative teens&#8212;used the checkboxes to send secret messages, including URLs, by encoding them in binary. This led to the discovery of a Discord group of these teens who creatively used the site to draw and communicate in unexpected ways, highlighting the creative potential of constrained online environments. This is a must-read thread!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Touz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Touz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 424w, https://substackcdn.com/image/fetch/$s_!Touz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 848w, https://substackcdn.com/image/fetch/$s_!Touz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 1272w, https://substackcdn.com/image/fetch/$s_!Touz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Touz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png" width="435" height="490.2260869565217" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:575,&quot;resizeWidth&quot;:435,&quot;bytes&quot;:361974,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Touz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 424w, https://substackcdn.com/image/fetch/$s_!Touz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 848w, https://substackcdn.com/image/fetch/$s_!Touz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 1272w, https://substackcdn.com/image/fetch/$s_!Touz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F399aef62-dc7f-4a65-87e4-787a5b463820_575x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://tldrsec.com/p/tldr-every-ai-talk-bsideslv-blackhat-defcon-2024">TL;DR: Every AI Talk from BSidesLV, Black Hat, and DEF CON 2024</a> (tl;dr sec) </strong>- WOW. If you want to know anything about security and AI, read this post! Fantastic work from the goat of cyber influencers, Clint Gibler.</p></li><li><p><strong><a href="https://techcrunch.com/2024/08/30/investors-are-already-valuing-openai-at-over-100b-on-the-secondaries-market/">Investors are already valuing OpenAI at over $100B on the secondaries market</a> (TechCrunch) - </strong>To think, I passed on this investment at a $23B valuation. Oops!</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (8/25/24)]]></description><link>https://www.thecyberwhy.com/p/tcw08252024</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw08252024</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 25 Aug 2024 16:28:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this week's edition of The Cyber Why, we explore what happens behind the scenes when a venture capital firm decides to invest in a startup, blush at the drama surrounding the collapsed CrowdStrike-Action1 deal, and consider the implications of a Microsoft-CrowdStrike summit and its potential impact on the industry. We take a brief look at the DOJ's suing Georgia Tech as a stark reminder of the consequences of neglecting cybersecurity compliance and learn that the Oracle fed Neo a cookie (TIL)! All this and much more in this week&#8217;s The Cyber Why!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong><a href="https://www.thecyberwhy.com/podcast">The Cyber Why POD - Now in 4k!</a> (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong><a href="http://thecyberwhy.com/">TCW Newsletter </a>and the <a href="https://www.thecyberwhy.com/podcast">TCW Podcast</a> both have 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Sequoia&#8217;s YouTube Investment Memo Circa 2005</h2><p><strong><a href="https://www.alexanderjarvis.com/the-confidential-youtube-investment-memo-by-sequoia-you-were-never-meant-to-see/">The confidential YouTube Investment Memo by Sequoia you were never meant to see</a> (Alexander Jarvis)</strong></p><p>Have you ever wondered exactly what happens after you&#8217;ve pitched your new company to a big-name investor? They disappear for a while, do a bunch of &#8220;research,&#8221; and if you are lucky, come back to you with an answer about their investment. But what really goes on behind the scenes? How do they grade you against the thousands of other investment opportunities they are likely to see in any given year?</p><p>Thanks to a lawsuit between Viacom and Google, we can read, in its entirety, the investment memo created by Sequoia partner Roelof Botha in 2005 as he and the firm analyzed their decision to invest in YouTube's super early seed stages.</p><p>What&#8217;s interesting in this article is the depth that Sequoia went to when analyzing the opportunity. The best investors aren&#8217;t just &#8220;dumb money&#8221; who follow simple signaling patterns to decide where to invest capital. The best approach will focus on the business fundamentals, the market, the competition, the founding team, AND the technology. Without all of that in alignment, a startup will never succeed. If you are building a startup and considering taking funding, you must read this piece and look at it through the eyes of the author. I promise that it will be enlightening!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MCWQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MCWQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MCWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg" width="324" height="223.56" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:414,&quot;width&quot;:600,&quot;resizeWidth&quot;:324,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;I'm doing research in venture capital, AMA | by Lawrence Lundy-Bryan |  Lunar Ventures | Medium&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="I'm doing research in venture capital, AMA | by Lawrence Lundy-Bryan |  Lunar Ventures | Medium" title="I'm doing research in venture capital, AMA | by Lawrence Lundy-Bryan |  Lunar Ventures | Medium" srcset="https://substackcdn.com/image/fetch/$s_!MCWQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MCWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d675b7-f60e-4f3a-b0d8-9783ad7a15d3_600x414.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>The Game of M&amp;A (aka A Game of Thrones)</h2><p><strong><a href="https://www.csoonline.com/article/3489695/crowdstrike-action1-deal-collapses-over-user-concerns.html">CrowdStrike-Action1 deal collapses over user concerns</a> (CSO Online)<br><a href="https://www.linkedin.com/feed/update/urn:li:activity:7232114274838396928/">Gur Talpaz comments on LinkedIn Post </a>(LinkedIn)</strong></p><p>The flames of the cyber drama dumpster fire continue to burn, as this week&#8217;s finger-pointing involves CrowdStrike vs. Action1. Cloud-based patch management and vulnerability remediation provider Action1 publically stated that it had rebuffed a $1B offer from Crowdstrike to acquire the company in the wake of the largest IT crash in history. Action1 placed the blame for the deal falling apart on feedback from customers after an email leaked about the acquisition. The customers felt the acquisition would erode trust in Action1, positioning them unfavorably in the market. But like any good who-done-it flick, we have a plot twist&#8230;</p><p>In response to Action1&#8217;s public statements, Gur Talpaz, VP of Corporate Development at Crowdstrike, took to Twitter to explain how he and presumably Crowdstrike see it. Crowdstrike barely had a 45-minute conversation with Action1 and never even approached an offer, let alone a deep discussion of acquisition. The LinkedIn post calls out Action1 for playing up a single meeting to get press and continued interest in their business. This move and the resulting counter-move bring into question other failed cybersecurity acquisitions over the last few years. It&#8217;s impossible to say exactly what happened when a he-said, she-said situation like this occurs, but it certainly raises doubt in one&#8217;s mind about so many other times this movie has played out.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/feed/update/urn:li:activity:7232114274838396928/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L8zQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 424w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 848w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 1272w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L8zQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png" width="1098" height="926" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:926,&quot;width&quot;:1098,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:223898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/feed/update/urn:li:activity:7232114274838396928/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L8zQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 424w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 848w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 1272w, https://substackcdn.com/image/fetch/$s_!L8zQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c728426-2cd3-459f-908d-16fed36e792a_1098x926.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Microsoft To Hold Cybersecurity Summit</h2><p><strong><a href="https://www.reuters.com/technology/cybersecurity/microsoft-host-cybersecurity-summit-after-crowdstrike-induced-it-outage-2024-08-23/">Microsoft to host cybersecurity summit after CrowdStrike-induced IT outage </a>(Reuters)<br><a href="https://www.cnbc.com/2024/08/23/microsoft-plans-september-cybersecurity-event-after-crowdstrike-outage.html">Microsoft plans September cybersecurity event to discuss changes after CrowdStrike outage</a> (CNBC)</strong></p><p>(<em>Katie pick</em>) Microsoft has announced its plan to host a cybersecurity summit in September, aiming to discuss how to improve security systems. After the faulty update that caused a global IT outage affecting 8.5 million devices,  it seems like an intelligent move&#8212;though one might wonder why it took <em>this</em> Microsoft gaff to make it happen. It also begs the question of whether Microsoft will finally take steps following the summit to improve its own security program and commercial technology offerings, which are the frequent targets of (successful) attacks.</p><p>CrowdStrike has indicated their involvement, which will be critical, given the widespread impact of the outage on the company&#8217;s huge install base. With billions in market value lost and legal claims piling up, there&#8217;s a lot on the line. Here&#8217;s hoping this summit leads to real solutions rather than just more talk.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Security Isn&#8217;t OPTIONAL - DOJ Has Said SO!</h2><p><a href="https://cyberscoop.com/georgia-tech-lawsuit-dod-contracts-cybersecurity/">DOJ sues Georgia Tech over allegedly failing to meet cyber requirements for DOD contracts</a> (Cyberscoop)</p><p>(<em>Katie pick</em>) It looks like Georgia Tech is in hot water with the Justice Department, and it's not for flunking an exam. Instead, the DOJ is pulling out the big guns by suing the university for allegedly skimping on some pretty important cybersecurity homework tied to Pentagon contracts.</p><p>The DOJ is dusting off the Civil War-era &#8220;False Claims Act&#8221; to advance this case, suggesting that the cybersecurity lapses at Georgia Tech's Astrolavos Lab were more "bug" than "feature." Apparently, not installing anti-malware software and submitting a questionable cybersecurity assessment score didn&#8217;t earn them any gold stars from the Pentagon.</p><p>For its part, Georgia Tech argues that the government was fully aware of its research's nature and that no classified information was ever at risk. According to Georgia Tech spokespeople, this case is more about miscommunication than malfeasance. It looks like we&#8217;ll have to wait and see how this one plays out over time!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XN06!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XN06!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XN06!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XN06!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XN06!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XN06!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg" width="400" height="316" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:316,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Georgia tech football Memes&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Georgia tech football Memes" title="Georgia tech football Memes" srcset="https://substackcdn.com/image/fetch/$s_!XN06!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XN06!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XN06!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XN06!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a53aa-7eab-40f9-a041-10915a182b39_400x316.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw08252024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw08252024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Neo Eats a Cookie</h2><p>For story #5 this week, I bring you a simple meme. I have been a huge fan of The Matrix since it first came out. I saw every one of them on release day in the theaters, and I have even tried to force them onto my children as some of the best movies in history (yes, I failed). I&#8217;ve even gone so far as to break down as much of each movie as I can from a technical perspective trying to find the hidden computer science and hacker references in the films. That being said - it was this week when I saw this meme and nearly spit out of my morning coffee. Now I have to go back and watch them all over again just in case I missed something else. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8AQ8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8AQ8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 424w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 848w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 1272w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8AQ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp" width="486" height="359.4375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:710,&quot;width&quot;:960,&quot;resizeWidth&quot;:486,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Neo having to accept a cookie before the Oracle will interact with him is such a fun piece of programme-related writing. THE GRACLE REQUIRED NEO TO ENABLE COGKIES&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Neo having to accept a cookie before the Oracle will interact with him is such a fun piece of programme-related writing. THE GRACLE REQUIRED NEO TO ENABLE COGKIES" title="Neo having to accept a cookie before the Oracle will interact with him is such a fun piece of programme-related writing. THE GRACLE REQUIRED NEO TO ENABLE COGKIES" srcset="https://substackcdn.com/image/fetch/$s_!8AQ8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 424w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 848w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 1272w, https://substackcdn.com/image/fetch/$s_!8AQ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbea8e2-50a5-4cfe-a951-7fc0bcacdc49_960x710.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.pymnts.com/technology/2024/tech-layoffs-reach-132000-8-months-into-2024/">Tech Layoffs Reach 132,000 8 Months Into 2024</a> (PYMTNS) - </strong>This has to be close to the bottom.. right? Please, someone, say it&#8217;s going to get better soon.</p></li><li><p><strong><a href="https://siliconangle.com/2024/08/05/cybersecurity-tool-sprawl-control-going-get-worse/">Cybersecurity tool sprawl is out of control &#8211; and it&#8217;s only going to get worse </a>(SiliconAngle) </strong>- This article almost made the top 5. The author does a great job breaking down the state of tool sprawl in modern enterprises.</p></li><li><p><strong><a href="https://arstechnica.com/information-technology/2024/08/crowdstrike-unhappy-with-shady-commentary-from-competitors-after-outage/">CrowdStrike unhappy with &#8220;shady commentary&#8221; from competitors after outage</a> (ARS Technica) </strong>- More pissing match drama. SentinelOne, PAN, and Crowdstrike are all going after each other like kindergarteners fighting for the one open swing.</p></li><li><p><strong><a href="https://franklyspeaking.substack.com/p/five-thoughts-from-defcon">Five Thoughts From DefCon</a> (Frank Wang) -</strong> I was recently having similar thoughts about going back to my technical roots, and Frank&#8217;s write-up expresses my thoughts very well. Thanks for the piece, Frank!</p></li><li><p><strong><a href="https://ventureinsecurity.net/p/cyber-optimist-manifesto-why-we-have">Cyber optimist manifesto: why we have reasons to be optimistic about the future of cybersecurity </a>(Venture In Security) -</strong> We could all use a dose of optimism right about now. Here&#8217;s what&#8217;s GOOD in cybersecurity today.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (8/19/24)]]></description><link>https://www.thecyberwhy.com/p/tcw08192024</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw08192024</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Mon, 19 Aug 2024 13:37:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/veGR-_UUhds" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After two full weeks of travel, one of which was Vegas for Hacker Summer Camp, I&#8217;m ready to dive back in and bring you our most exciting articles and stories of the week. </p><p>In this issue of The Cyber Why newsletter, we surface the &#8220;3 Billion People&#8221; hack that &#8220;may not be&#8221; at National Public Data, Tyler&#8217;s views on hitting the bottom of the VC investment cycle (tl;dr it&#8217;s up from here), the White House spends a whopping $11M on open source supply chain security (that&#8217;s all?!), measuring security debt as a new paradigm for understanding risk, and last but not least, what happens when a Tesla Cybertruck ends up in the hands of a Chechen Warlord (oh my!). All this and more in this week&#8217;s The Cyber Why!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong><a href="https://www.thecyberwhy.com/podcast">The Cyber Why POD - Now in 4k!</a> (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong><a href="http://thecyberwhy.com/">TCW Newsletter </a>and the <a href="https://www.thecyberwhy.com/podcast">TCW Podcast</a> both have 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep, 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>A US-Wide Compromise That May Not Be Real</h2><p><strong><a href="https://www.troyhunt.com/inside-the-3-billion-people-national-public-data-breach/">Inside the "3 Billion People" National Public Data Breach</a> (Troy Hunt)</strong></p><p>Is it real? The &#8220;billions of compromised accounts&#8221; question. A massive data breach involving National Public Data (NPD) has sent shockwaves through the internet, but the true extent and legitimacy of the leaked information remains a mystery.</p><p>Initially, hackers claimed to have stolen data on nearly 3 billion people, including sensitive information like Social Security numbers. However, as more details emerge, a complex puzzle forms. Different batches of data appeared online, varying in size and content. Some information seemed accurate, while other parts appeared to be random or even fabricated. As outlined by blog author Troy Hunt, the challenge lies in determining which data is genuine and which is simply noise added to create confusion. With conflicting reports and a lack of transparency from those involved, unraveling the truth about this breach is proving to be an arduous task. Thanks, Troy, for tracking this one down and providing a life preserver in a murky pond.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Venture Bottom or Death Spiral?</h2><p><strong><a href="https://carta.com/blog/vc-fund-performance-q1-2024/#download-the-full-report">VC Fund Performance: Q1 2024</a> (Carta Report)</strong></p><p>In an article posted on August 16th, the Carta data research team noted that venture capitalists are having a rough go of it. With interest rates soaring and IPOs as scarce as a meth head&#8217;s teeth, money managers are in dire need of returns. Based on a view into over 1,803 venture funds, Carta's latest report paints a really tough picture. Funds from 2022 have deployed only 43% of their cash after two years, the slowest pace ever. And don't even get started on returns &#8211; less than 10% of 2021 funds have seen a dime back from their investments after three years.</p><p>If you think things are bad for VCs, wait until you hear about the businesses they are funding. The data on graduation rates is downright depressing. Fewer and fewer seed-stage companies are making it to Series A, suggesting a sad outlook for many new ventures.  Are we simply at the bottom of a venture down cycle, or should we be worried about something more drastic occurring? In my opinion, we should see a positive bounce over the next few vintages. Fingers crossed!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vZwd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vZwd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 424w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 848w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 1272w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vZwd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png" width="1456" height="830" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:830,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:499415,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vZwd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 424w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 848w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 1272w, https://substackcdn.com/image/fetch/$s_!vZwd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda9b7c6c-c90d-4953-9429-a1ac578772f4_1680x958.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>A Whole $11M for Open Source Security in Critical Infrastructure?!?!</h2><p><strong><a href="https://www.cybersecuritydive.com/news/white-house-11-million-secure-open-source/724223/">White House details $11M plan to help secure open source</a> (Cybersecurity Dive)</strong></p><p>(<em>Katie Pick</em>) Last week during DEFCON 32, National Cyber Director Harry Coker Jr. revealed a plan by the White House and Department of Homeland Security (DHS) that will focus on helping secure open source software used in operational technology. Coker shared that the plan is to invest $11M USD in a program they&#8217;re calling the &#8220;Open Source Software Prevalence Initiative.&#8221;</p><p>Now, on the one hand, this is great! Any time initiatives like this come down from the top, it&#8217;s a signal to public and private organizations that it&#8217;s time to step up their game. In the case of open source &#8212;&nbsp;or open source-based &#8212; software, it&#8217;s <em>past</em> time. The threat surface is enormous. According to various sources, attacks on software, particularly those targeting the software supply chain, have increased by 300-400% in the last three years. Driven by increased reliance on open source codebases and the complexity of modern software development, there are no signs of these attacks slowing down. Given that critical infrastructure (CI) increasingly relies on traditional software (versus purpose-built, air-gapped components), the sector is at least as vulnerable to software and supply chain attack as any other industry (i.e., <em>very</em> high risk) or likely higher, given the impact of a CI compromise. <br><br>On the other hand, what does it say that the government is offering less than most seed rounds for organizations to make substantive changes in software development and open source security? Though this isn&#8217;t the only initiative or government-supplied help organizations can get in this realm, it feels a little like offering a single nail to fix a leaky bucket.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Security Debt - A Metric NOW With Meaning</h2><p><strong><a href="https://www.digitalocean.com/blog/digitalocean-security-debt">Contextual Vulnerability Management With Security Risk As Debt</a> (Ari Kalfus and Tim Lisko)</strong></p><p>Vulnerability management has existed since the birth of cybersecurity as an industry. As new vulnerabilities are discovered, enterprises have to determine if they are affected and then remediate those issues programmatically. Over the years, things have gotten way more complicated than simply fixing issues when they arise. The growth in the number of CVEs discovered each year has become overwhelming. To make matters worse, security teams have no way to properly prioritize the fixes without severely impacting the output of the business as a whole.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NrFA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NrFA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 424w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 848w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 1272w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NrFA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png" width="532" height="328.4807692307692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:899,&quot;width&quot;:1456,&quot;resizeWidth&quot;:532,&quot;bytes&quot;:120320,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NrFA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 424w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 848w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 1272w, https://substackcdn.com/image/fetch/$s_!NrFA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7792980d-3165-4e72-a339-828e9623bd83_1972x1218.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Enterprise security groups need a better way to create urgency for remediation within their engineering and development teams without being perceived as the group slowing down business. Enter the concept of &#8220;security debt.&#8221; Much like financial or technical debt, security debt can be measured by adding context to the decision tree for recommended remediation time and then adding a time element (let&#8217;s call this &#8220;security interest&#8221;) to the equation so that the longer issues remain, the more security debt is accumulated. DigitalOcean security leaders Ari Kalfus and Tim Lisko wrote a very interesting blog post outlining how they are working towards implementing a security debt metric at their firm. It&#8217;s a fantastic read, and I love the innovation around metrics. We can adapt this type of math to many more fields, and I look forward to seeing how this grows over time.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw08192024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw08192024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>A Cybertruck War Machine Is A BAD Idea</h2><p><strong><a href="https://nypost.com/2024/08/17/world-news/tesla-cybertruck-with-machine-gun-flaunted-by-chechen-war-lord/">Ecstatic warlord mounts machine gun on Cybertruck, invites Musk to visit after hailing billionaire&#8217;s &#8216;genius&#8217;</a> (NY Post)</strong></p><p>A Chechen warlord, Ramzan Kadyrov, has acquired a Tesla Cybertruck and mounted it with a massive machine gun on the back. Please try to ignore any discussion or implication to the actual conflict in Ukraine and give this video a watch simply for the stupidity that is a Cybertruck with a machine gun. There are TONS of Cybertruck fails on YouTube and after you watch this video, go check out this one that features <a href="https://www.youtube.com/watch?v=HZ0XbEmskD8">an old-school pickup truck saving the day when a cybertruck gets STUCK!</a></p><div id="youtube2-veGR-_UUhds" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;veGR-_UUhds&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/veGR-_UUhds?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.wired.com/story/infrared-laser-microphone-keystroke-surveillance/">Watch How a Hacker&#8217;s Infrared Laser Can Spy on Your Laptop&#8217;s Keystrokes</a> (Wired) - </strong>Sam Kamkar of <a href="https://en.wikipedia.org/wiki/Samy_Kamkar">MySpace Worm fame</a> resurfaces a legend from the 90s and brings it to life! I&#8217;ve been &#8220;hearing this for decades.&#8221; Now it&#8217;s real.</p></li><li><p><strong><a href="https://orca.security/resources/blog/orca-ai-goat-open-source-environment-owasp-risks/">Meet AI Goat: The First Open Source AI Security Learning Environment Based on the OWASP Top 10 ML Risks</a> (Orca Security) </strong>- An exciting environment for learning about AI security. While I like education, I&#8217;m more interested in the &#8220;how&#8221; to secure it problem.</p></li><li><p><strong><a href="https://x.com/dguido/status/1824872062068174952">Fuzzing Bests Formal Verification</a> (Dan Guido) -</strong> Super technical yet awesome. I guess my formal methods courses really were an annoying waste of time! Long Live &#8220;<a href="https://en.wikipedia.org/wiki/Z_notation#:~:text=The%20Z%20notation%20/%CB%88z,computer%2Dbased%20systems%20in%20general.">ZED</a>!&#8221;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/dguido/status/1824872062068174952" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YbsZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 424w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 848w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 1272w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YbsZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png" width="580" height="344" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:344,&quot;width&quot;:580,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:119767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/dguido/status/1824872062068174952&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YbsZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 424w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 848w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 1272w, https://substackcdn.com/image/fetch/$s_!YbsZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9c2c22-504f-45c7-ba02-0ff149a381bf_580x344.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (8/4/24)]]></description><link>https://www.thecyberwhy.com/p/tcw08042024</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw08042024</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 04 Aug 2024 15:17:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/H6Xfvm2f8L8" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Happy day before Blackhat week! The annual trek to Las Vegas, lovingly known as &#8220;Hacker Summer Camp,&#8221; is back and ready to educate, innovate, dehydrate, and over-stimulate you. It&#8217;s a time to make new friendships and rekindle old ones. I fly in Monday morning and will be there through Friday if you want to grab a coffee. Hit me up in the DMs, and I&#8217;ll give you a free The Cyber Why sticker! Now onto the newsletter!</p><p>This week in The Cyber Why, we bring you a new record for a single ransomware amount, worry about Crowdstrike&#8217;s future potential legal woes, update you on the cyber M&amp;A landscape, watch as Ferrari brakes hard on Deepfake scams, and last and certainly least, we bring you the CyberCasket - Tesla Tech Bros REJOICE!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IBc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" width="384" height="150.58823529411765" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1020,&quot;resizeWidth&quot;:384,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Get the most from your security team&#8217;s email alert budget</strong></em></p><p>Relying on built-in controls or traditional blockers will inevitably lead to more noise than your incident response team can handle.</p><p>Material Security takes a pragmatic approach to email security &#8211; stopping new flavors of phishing and pretexting attacks before reaching the user&#8217;s mailbox, while searching through everyone else&#8217;s mailbox for similar messages in a campaign. What gets surfaced to your team are the highest-value cases to investigate with all the context and reach consolidated into a single view. </p><p>Free up more of your alert budget so your team can spend it on what really matters. See how much time you can give back to your security team with Material.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240801-the-cyber-why&quot;,&quot;text&quot;:&quot;Visit Material Security&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240801-the-cyber-why"><span>Visit Material Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Angels or Demons - A Ransomware Record</h2><p><strong><a href="https://www.forbes.com/sites/daveywinder/2024/07/31/record-breaking-75-million-ransom-paid-to-dark-angels-gang/">Record-Breaking $75 Million Ransom Paid To Dark Angels Gang</a> (Forbes)</strong></p><p>Well, well, well. The Dark Angels gang just hit the jackpot, raking in a whopping $75 million, a new record for a single ransomware amount. This eye-watering sum smashes the previous record of $40 million paid by CNA Financial in 2021. Apparently, these "angels" are more like demons, targeting a select few high-value organizations and making off with 10-100 terabytes of data. Talk about going big or going home!</p><p>Meanwhile, global ransomware attacks are up 18% year-on-year, with the US getting hammered 93% more than last year. Manufacturing is taking it on the chin, suffering more than twice as many attacks as healthcare and technology combined. But hey, at least we have "Ransomware Awareness Month" to save us! Because nothing says "effective cybersecurity" like a gimmicky PR campaign, right? Maybe instead of awareness months, companies should try being aware every day and patch their damn systems before the Dark Angels come knocking.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>CrowdStrike&#8217;s Legal Woes Are Just Beginning </h2><p><strong><a href="https://www.wsj.com/business/airlines/delta-ceo-says-crowdstrike-tech-outage-costs-could-reach-500-million-3b7f5a13">Delta CEO Says CrowdStrike Tech Outage Cost It $500 Million</a> (WSJ)<br><a href="https://www.theverge.com/2024/8/1/24210680/crowdstrike-microsoft-outage-delta-lawsuit-class-action-damages">Delta CEO: &#8216;When was the last time you heard of a big outage at Apple?&#8217;</a> (The Verge)<br><a href="https://www.forbes.com/sites/kateoflahertyuk/2024/08/02/crowdstrike-is-now-being-sued-by-investors/">CrowdStrike Is Now Being Sued By Investors</a> (Forbes)</strong></p><p><em>(Rick Pick)</em> It&#8217;s been a rough two weeks for CrowdStrike and its customers. This week, we saw legal responses to the incident emerge. First, Delta's CEO came out swinging. He claimed that the outage would cost Delta Airlines $500 million and that they would seek legal damages from both CrowdStrike and Microsoft. Delta took longer to recover than any other airline. Additionally, the Plymouth County Retirement Association pension fund filed a class action lawsuit (<a href="https://www.bernlieb.com/wp-content/uploads/2024/07/20240731-91ea4496ec7c.pdf">PDF</a>) in Texas. The lawsuit claims that CrowdStrike: </p><blockquote><p>"... repeatedly touted the efficacy of the Falcon platform while assuring investors that CrowdStrike&#8217;s technology was &#8220;validated, tested, and certified.&#8221; This complaint alleges that these statements were false and misleading..."</p></blockquote><p>I&#8217;m not a lawyer and don&#8217;t play one on TV, so I won&#8217;t wade into waters over my head, but I can say that these cases, along with others that will follow, are a costly distraction for a company that must regain the trust of its customers. These cases won&#8217;t be resolved quickly, so this embarrassing outage will continue to periodically make its way into the headlines. I&#8217;m interested in reading upcoming SEC Form 8-K filings to see how the outage has impacted other public companies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aPIm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aPIm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 424w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 848w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aPIm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png" width="446" height="280.5879120879121" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:916,&quot;width&quot;:1456,&quot;resizeWidth&quot;:446,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Funniest CrowdStrike Outage Memes Giving the Blue Screen - Funny Gallery&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Funniest CrowdStrike Outage Memes Giving the Blue Screen - Funny Gallery" title="The Funniest CrowdStrike Outage Memes Giving the Blue Screen - Funny Gallery" srcset="https://substackcdn.com/image/fetch/$s_!aPIm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 424w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 848w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!aPIm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a1f162-9b6b-4a2a-a332-5e4c558219be_1720x1082.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Cybersecurity Acquisitions Drop Dramatically&#8230;or Have They?</h2><p><strong><a href="https://www.securityweek.com/securityweek-analysis-178-cybersecurity-ma-deals-announced-in-first-half-of-2024/">Security Week Analysis: 178 Cybersecurity M&amp;A Deals Announced in First Half of 2024</a> (Security Week)</strong></p><p><em>(Katie Pick)</em> Eduard Kovacs is up to his always-excellent analysis of the cybersecurity market. In this piece, published on July 29, 2024, Kovacs shares data about cybersecurity M&amp;A activity in the first half of 2024. He specifically shares that the number of deals has dropped dramatically &#8212; ~75% since H2 2021 and 17% since H1 2023.</p><p>According to the analysis, Europe's companies are the hardest hit, while M&amp;A for companies in Australia, Canada, Germany, and Israel has stayed relatively steady.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6DdQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6DdQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 424w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 848w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 1272w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6DdQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png" width="464" height="355.54305799648506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:872,&quot;width&quot;:1138,&quot;resizeWidth&quot;:464,&quot;bytes&quot;:168336,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6DdQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 424w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 848w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 1272w, https://substackcdn.com/image/fetch/$s_!6DdQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef3bba4f-9ded-4161-8cbf-2c4cb54f3b6e_1138x872.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What&#8217;s interesting about the analysis, however, is that while the&nbsp;<em>total</em>&nbsp;number of deals has shrunk, the valuations of acquired companies have expanded. Specifically, six deals were valued at over $1B USD. Kovacs writes, &#8220;It&#8217;s worth pointing out that the number of deals exceeding $1 billion is already the same as in the entire year of 2023.&#8221;</p><p>We&#8217;ll have to watch the trends over the next few quarters, but if deal sizes continue to increase, we're either seeing overvaluation (again) in the cybersecurity market or a reshaping of the market. A reshaping could mean more small companies get scooped up for big bucks or squashed by the larger players before they even have a chance to get there.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Ferrari Slams The Brakes On AI Deepfake Scam</h2><p><strong><a href="https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo">&#8216;I Need to Identify You': How One Question Saved Ferrari From a Deepfake Scam</a>  (Bloomberg)<br><a href="https://autos.yahoo.com/ferrari-ceo-impersonated-ai-deepfake-183000485.html">Ferrari CEO Impersonated by AI in Deepfake Scam Attempt</a> (Yahoo)<br><a href="https://www.thedrive.com/news/ferrari-thwarted-an-ai-deepfake-scammer-posing-as-its-ceo-with-an-age-old-trick">Ferrari Thwarted an AI Deepfake Scammer Posing as Its CEO With an Age-Old Trick</a> (The Drive)</strong></p><p><em>(Rick Pick)</em> The deepfake problem is accelerating. <a href="https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html">Earlier this year</a>, a Hong Kong finance worker got taken for a $25 million joyride after joining a multi-person video conference with fake participants. This week, Ferrari was in the crosshairs. A deepfake scammer reached out to a Ferrari executive via WhatsApp but was thwarted when the executive asked a question only Ferrari&#8217;s CEO could answer. The bar for creating deepfakes is getting lower. Security Awareness Training has become a compliance checkbox punchline, but performing targeted deepfake training for executives is something that defenders need to do. If you are at Summer Camp in Vegas next week, the<a href="https://aivillage.org/events/2024_talks"> </a>DEF CON <a href="https://aivillage.org/events/2024_talks">AI Village</a> will have a Deepfake Demo lab. <a href="https://www.darpa.mil/">DARPA</a> will even have a deep fake analysis system there. I&#8217;ll be there too, so say hi if you are around!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw08042024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw08042024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Tech Bros Rejoice - The CyberCasket Is Launched</h2><p><strong><a href="https://go.titancasket.com/hypercasket/">The CyberCasket</a> (Titan Casket)</strong></p><p>Starting today, if you kick the bucket, you won&#8217;t have to give up that Tesla vibe; instead, get yourself a HyperCasket (aka CyberCasket). With a recessed latch similar to Tesla doors, vegan leather (what is vegan leather anyway?), and a 12-gauge stainless steel exterior to match your cybertruck, you can now rest in peace in an amazing CyberCasket. Don&#8217;t forget to purchase the optional seatbelt and self-burying technology (no lie, these are on the ordering form.) For only $9,999 (add-ons not included), you, too, can spend the rest of eternity in Elon Musk&#8217;s good graces! Here&#8217;s a copy of one of the user reviews from their site:</p><blockquote><p>I passed away 2 months ago and decided to go with the CyberCasket. Let me tell you it's the BEST PURCHASE EVER! I decided to upgrade to the self-burying model as I didn't want to pay an opening and closing fee at the cemetery. I would recommend purchasing the seatbelt as well as the ride tends to be a bit bumpy, I did fall out of the casket once. The Wi-Fi cuts in and out at times and makes it a bit difficult to post my daily TikTok's but other than that this is a great product, if I were to die a second time, I would definitely purchase this product again with the seat belt added! &#8594; <a href="https://titancasket.com/products/hypercasket#judgeme_product_reviews">link to actual review</a></p></blockquote><div id="youtube2-H6Xfvm2f8L8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;H6Xfvm2f8L8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/H6Xfvm2f8L8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/how-new-age-hackers-are-ditching-old-ethics">How New-Age Hackers Are Ditching Old Ethics </a>(Dark Reading) - </strong>Times have certainly changed. When I was a &#8220;hacker,&#8221; web defacements were about as bad as we got. For-profit never even hit our radar. Today the ethics are out the window as younger attackers gun straight for the profits.</p></li><li><p><strong><a href="https://www.ranum.com/security/computer_security/editorials/monoculture-hype/index.html">Monoculture Hype</a> (Marcus J. Ranum) - </strong>Marcus Ranum, cyber security luminary and inventor of many cyber concepts and technologies wrote a 2003 retort to the monoculture paper by Geer et al. that we discussed in last week&#8217;s The Cyber Why <a href="https://www.thecyberwhy.com/p/tcw-07272024">here</a>. It&#8217;s short, but I&#8217;m glad I found it, as it&#8217;s an interesting counterpoint to the original piece. I wonder how Marcus perceives the issues after the Crowdstrike debacle.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (7/27/24)]]></description><link>https://www.thecyberwhy.com/p/tcw-07272024</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw-07272024</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 28 Jul 2024 01:26:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>As I watch the opening ceremonies and early events of the Olympic games, I am struck by just how many countries and people there are in the world. I am in awe that almost 5,000 of you have opted in to receive our little slice of commentary every week. I appreciate each of you who follow our writing, and I want to say thank you for being along for the ride. We love you all! Now, onto the fun&#8230;</p><p>This week in The Cyber Why, we bring you a phenomenal cyber market research report from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;4ee37fe8-98dd-4528-b508-d9989e545068&quot;}" data-component-name="MentionToDOM"></span>, discuss a unique remote work inside threat model, flashback to 2003 and learn about concentration risk and homogeneity, debate the WHY behind the G-Wiz break up, and for story number five, Southwest Airlines can dodge bullets. All this and more in this week&#8217;s TCW!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IBc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" width="418" height="163.92156862745097" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1020,&quot;resizeWidth&quot;:418,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Get the most from your security team&#8217;s email alert budget</strong></em></p><p>Relying on built-in controls or traditional blockers will inevitably lead to more noise than your incident response team can handle.</p><p><strong><a href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240801-the-cyber-why">Material Security</a></strong> takes a pragmatic approach to email security &#8211; stopping new flavors of phishing and pretexting attacks before reaching the user&#8217;s mailbox, while searching through everyone else&#8217;s mailbox for similar messages in a campaign. What gets surfaced to your team are the highest-value cases to investigate with all the context and reach consolidated into a single view.&nbsp;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240801-the-cyber-why&quot;,&quot;text&quot;:&quot;Visit Material Security&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240801-the-cyber-why"><span>Visit Material Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>More Evidence of Market Consolidation</h2><p><strong><a href="https://pulse.latio.tech/p/wtf-is-cloud-application-detection">WTF is Cloud Application Detection Response</a> (Latio Tech James Berthoty)</strong></p><p>I rarely read a report, especially one from an independent analyst, that nails a future prediction so directly on the head that you can&#8217;t help but know they are right. This piece by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;8c952ed6-9be1-4ed4-9cef-40a7ffc9cdbc&quot;}" data-component-name="MentionToDOM"></span> from <a href="http://latio.tech">Latio Tech</a> is absolutely amazing. In addition to nailing the technical requirements for a product roll-up in application and cloud detection and response, he also manages to go from 7+ acronyms down to just one (THANK GOD!)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9xeF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9xeF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 424w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 848w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 1272w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9xeF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png" width="424" height="342.46153846153845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:735,&quot;width&quot;:910,&quot;resizeWidth&quot;:424,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9xeF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 424w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 848w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 1272w, https://substackcdn.com/image/fetch/$s_!9xeF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97428822-0b2b-4870-8afa-d17a46c4df08_910x735.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Latio Tech has a strict &#8220;one new acronym per 7 dead ones&#8221; rule.</figcaption></figure></div><p>This report makes a very strong case that the following seven cyber markets should be rolled up into something more significant. They constitute a group of features and isolated products today and shouldn&#8217;t over the long term.</p><ol><li><p>Application Detection Response (ADR)</p></li><li><p>Cloud Detection Response (CDR)</p></li><li><p>Kubernetes Detection Response (KDR)</p></li><li><p>Cloud Workload Protection Platform (CWPP)</p></li><li><p>Cloud Native Application Protection Platform (CNAPP)</p></li><li><p>Continuous Threat Exposure Management (CTEM)</p></li><li><p>API Security</p></li></ol><p>As an industry, cybersecurity builds too many point products and not nearly enough groupings of features that make singular, powerful solutions. Cybersecurity has only existed for about 30 years (give or take). When an industry is young, solving very pointed problems and selling products that help customers solve unique issues makes sense.  It&#8217;s a time of rapid innovation and expansion of new ideas. As markets mature, they group smaller, feature-sized products into platforms that deliver outsized value. Eventually, highly mature markets will consolidate into three dominant market participants. </p><p>We have entered the start of an era where cybersecurity must come to terms with a decrease in product counts and a simultaneous increase in customer value. The next decade of cybersecurity is going to be fun to watch as vendors broaden their technologies by acquisition and adjacent market consolidation.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>The Hermit Kingdom Makes Headlines</h2><p><strong><a href="https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals">North Korean Government Hacker Charged for Involvement in Ransomware Attacks Targeting U.S. Hospitals and Health Care Providers</a> (DOJ)<br><a href="https://cyberscoop.com/north-korean-hacking-group-makes-waves-to-gain-mandiant-fbi-spotlight/">North Korean hacking group makes waves to gain Mandiant, FBI spotlight</a> (Cyberscoop)<br><a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us">Incident Report Summary: Insider Threat</a> (Knowbe4)<br><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine">APT45: North Korea&#8217;s Digital Military Machine </a>(Mandiant)</strong></p><p><em>(Rick Pick) </em>North Korea made headlines this week via a couple of stories. First, the Security Awareness Training company <a href="https://www.knowbe4.com/">Knowbe4</a> released a <a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us">blog</a> discussing how they hired a remote software engineer who turned out to be a North Korean insider threat. The threat actor was a "real person using a valid but stolen US-based identity." Kudos to Knowbe4 for releasing this blog. </p><p>Next up, the Department of Justice indicted a North Korean, Rim Jong Hyok, for "his involvement in a conspiracy to hack and extort U.S. hospitals and other health care providers." North Korea has long funded its regime through cybercrime, and this case is another potential example. Hyok is a member of the threat actor group APT45. Mandiant also released a deep dive on the group <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine">here</a>.</p><p><em>Editors Note: It&#8217;s crazy to me how easy it is to get an inside threat into US-based enterprises. This risk has only increased with the rise of remote work. This type of threat is real and very difficult to discover. Be vigilant out there, people! BTW: TIL what the Hermit Kingdom is!</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>CyberInsecurity: The Cost of Monopoly</h2><p><strong><a href="https://franklyspeaking.substack.com/p/what-the-crowdstrike-outage-means">What the Crowdstrike outage means for the security industry?</a> (Frankly Speaking)<br><a href="http://geer.tinho.net/cyberinsecurity.pdf">CyberInsecurity: The Cost of Monopoly</a> (Dan Geer and others)</strong></p><p>By now, everyone has heard of the global IT outage caused by a software update issued by the cyber security vendor Crowdstrike. The cyber and IT social media universe has been abuzz discussing how it happened, how to fix the issue so it doesn&#8217;t happen again, and what the long-term impact on the business world will be. </p><p>On the back of the fallout, the main concern that comes to my mind is not about hacks, updates, or technology failure - instead, it is the concept of homogeneity. When a system that contains a given level of risk is deployed uniformly throughout an entire section of space, the risk to that space increases. To state it in a &#8220;less nerdy&#8221; way, the risk of issue or compromise grows if you deploy the same software everywhere. Attackers love concentration risk. It gives them a higher level of potential compromise with less effort.</p><p>The Crowdstrike issue was exacerbated by concentration risk because, as of January 31, 2023, CrowdStrike had 23,019 subscription customers, a 41% increase year over year. They analyze <strong>over 30 billion</strong> endpoint events daily from millions of sensors across 176 countries. That&#8217;s a MASSIVE deployment size and a MASSIVE concentration risk.  High concentration risk plus an automatic update system make for a perfect path to MASSIVE damage.</p><p>This problem reminds me of the 2003 paper written by Dan Geer et al. entitled &#8220;<a href="http://geer.tinho.net/cyberinsecurity.pdf">CyberInsecurity: The Cost of Monopoly.</a>&#8221; I remember the time vividly as I was working with Dan at @stake when he published the paper for which he was famously fired. Looking back, it seems like he was right; he just had the wrong company in his line of sight. This seminal paper is a must-read. Go check it out!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R-Du!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R-Du!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R-Du!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg" width="328" height="246" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:480,&quot;resizeWidth&quot;:328,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dan Geer - 1997 Opening Statement to Congress&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dan Geer - 1997 Opening Statement to Congress" title="Dan Geer - 1997 Opening Statement to Congress" srcset="https://substackcdn.com/image/fetch/$s_!R-Du!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R-Du!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a6a301-a322-441c-a654-fb5dc8f34a8d_480x360.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The great Dr Geen presented to Congress in 1997</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Security Theater Continues with Wiz Rejecting Google Offer</h2><p><strong><a href="https://www.wsj.com/tech/google-talks-to-acquire-cybersecurity-startup-wiz-fall-apart-64194e9e">Google Talks to Acquire Cybersecurity Startup Wiz Fall Apart</a> (Wall Street Journal)<br><a href="https://www.investopedia.com/google-talks-to-buy-wiz-for-usd23b-reportedly-end-8682043">Google Talks to Buy Wiz for $23B Reportedly End</a> (Bloomberg)<br><a href="https://www.bloomberg.com/news/articles/2024-07-23/cyber-firm-wiz-rejects-alphabet-s-23-billion-offer-seeks-ipo?embedded-checkout=true">Wiz Rejects Google&#8217;s $23 Billion Offer, Seeks IPO Instead </a>(FOO)</strong></p><p>(<em>Katie pick</em>) By now, you&#8217;ve definitely heard the news: Wiz walked away from a $23 billion dollar acquisition offer from Alphabet (Google&#8217;s parent company) to focus on preparing for an IPO instead. The initial announcement about the intent to acquire shocked the security community, both because of the sheer financials thrown around in media publications and because the deal, had it gone through, would have drastically changed the cloud vendor security landscape. </p><p>This was never a typical acquisition proposal, so the &#8220;ifs&#8221; were abundant.</p><p>But what I find most interesting is the timing of the offer and the decline. Few founders would reject the kind of money offered. Even with all the funding raised ($1.9B USD to date), the multiples were off the charts, especially for a four-year-old company. But to reject that kind of deal <em><strong>so quickly</strong></em> indicates to me that some sort of security theater may have been at play. In other words, Wiz might never have had any intention of selling. The founders have been bullish on this topic from the start &#8212; their goal is to become the biggest security company of all time. So why allow the media to get into a frenzy? Why even let it get to the media if the Wiz team had already decided to stay solo? </p><p>The short answer: Press and media attention. Market attention. All right before filing for IPO. I suppose it&#8217;s no different than an NFL coach hyping up his team right before the &#8220;Big Game.&#8221; But is this what we need in cybersecurity? Wouldn&#8217;t it just be better to build products that are really really really good and save the drama for the Kardashians?</p><p><em>Editors Note: Do you think it was security theater or was Google or Wiz spooked by some other reason? Comments below&#8230;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw-07272024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw-07272024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Southwest Airlines - Dodging Bullets, Baby!</h2><p><strong><a href="https://www.yahoo.com/tech/windows-version-1992-saving-southwest-171922788.html">A Windows version from 1992 is saving Southwest&#8217;s butt right now</a> (Yahoo)</strong></p><p>If this is true (it may not be), it&#8217;s absolutely NUTS. Southwest is the only airline that didn&#8217;t go down or suffered significant issues during the Crowdstrike debacle last week, and the reason is&#8230; get this&#8230; they still use Windows 95 and 3.11? I am not sure I believe the story, which is why I put it in as Story #5 this week, but if it&#8217;s true, they have a lot of work to do. Here&#8217;s a pick of Southwest Airlines when they learned they had dodged a bullet. (HT <a href="https://x.com/suttonimpaQt/status/1814277613906477096">SuttonimpaQT</a>)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9QGD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9QGD!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 424w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 848w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 1272w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9QGD!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif" width="532" height="216.125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:130,&quot;width&quot;:320,&quot;resizeWidth&quot;:532,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Homelander Alright on Make a GIF&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Homelander Alright on Make a GIF" title="Homelander Alright on Make a GIF" srcset="https://substackcdn.com/image/fetch/$s_!9QGD!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 424w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 848w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 1272w, https://substackcdn.com/image/fetch/$s_!9QGD!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbf5babe-503f-4be8-b6b3-99514e2f2d2b_320x130.gif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (7/13/24)]]></description><link>https://www.thecyberwhy.com/p/wwrtw-071324</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/wwrtw-071324</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sat, 13 Jul 2024 20:52:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome back, Cyber Why readers! Buckle up because this week&#8217;s newsletter is a rollercoaster of digital drama and tech intrigue. We kick off with the fall of hacker kingpin &#8216;Tank,&#8217; whose ego finally caught up with him. Then, we dive into the murky waters of a $25M auto dealer ransom&#8212;CDK Global, we're looking at you! Next, we take a nostalgic detour with a $200K Lego heist that would make any childhood collector weep. For our finance and startup geeks, we&#8217;ve got a deep dive into the evolving world of SaaS and AI pricing strategies, predicting seismic shifts in the industry. And for a sprinkle of absurdity, we present Story #5 - VR shoes that promise to take you everywhere and nowhere at the same time. Let&#8217;s dig in and dissect the chaos together!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IBc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" width="384" height="150.58823529411765" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1020,&quot;resizeWidth&quot;:384,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Email security that protects from the outside in and inside out</strong></em></p><p>There&#8217;s more than one way in to exploit email as an attack vector. Plus, even more to target once inside the mailbox. Material Security takes a holistic approach to email security that covers the full threat landscape &#8211; stopping new flavors of phishing and pretexting attacks in their tracks, while also protecting accounts and data from exploit or exposure.</p><p>Visit <a href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240711-the-cyber-why">material.security</a> to learn more about their multi-layered detection and response toolkit for email.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240711-the-cyber-why&quot;,&quot;text&quot;:&quot;Visit Material.Security&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240711-the-cyber-why"><span>Visit Material.Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe here and get TCW free of charge! Yep 100% FREE (unless you wanna pay).</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>When Ego Takes Over - Criminals Fall</h2><p><strong><a href="https://www.wired.com/story/vyacheslav-igorevich-penchukov-tank-zeus-malware-sentencing/">Notorious Hacker Kingpin &#8216;Tank&#8217; Is Finally Going to Prison</a> (WIRED)</strong></p><p>I&#8217;m a sucker for the &#8220;Hacker Kingping&#8221; going to jail story. We have reported on a number of them over the last year and a half, including early details on this particular arrest, and I still find them absolutely intriguing. What would make a person go down a path of crime that is so heinous and despicable? People think the answer lies in greed and money, but if you read between the lines, you often find that the real reason most of these disgusting people do what they do is ego.</p><p>Vyacheslav Penchukov, a Russian national, was the mastermind behind the Zeus malware operation. He orchestrated the creation and distribution of malware that infected millions of computers worldwide. Penchukov aimed to steal banking information and commit financial fraud, generating substantial illegal profits. He was involved from November 2018 to at least February 2021, officials say. Investigators found he kept a spreadsheet detailing his $19.9 million income in 2021 alone.</p><p>That&#8217;s pure ego - nothing more. I, for one, am glad to see this guy going away for such a long time. Enjoy your time in jail, Vyacheslav; I don&#8217;t think DJs are needed very often on the inside. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jbmp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jbmp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 424w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 848w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 1272w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jbmp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png" width="330" height="260.6008583690987" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:368,&quot;width&quot;:466,&quot;resizeWidth&quot;:330,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Top Zeus Botnet Suspect &#8220;Tank&#8221; Arrested in Geneva &#8211; Krebs on Security&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Top Zeus Botnet Suspect &#8220;Tank&#8221; Arrested in Geneva &#8211; Krebs on Security" title="Top Zeus Botnet Suspect &#8220;Tank&#8221; Arrested in Geneva &#8211; Krebs on Security" srcset="https://substackcdn.com/image/fetch/$s_!Jbmp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 424w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 848w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 1272w, https://substackcdn.com/image/fetch/$s_!Jbmp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99337511-8b3b-4c82-aee0-14d401a3e3ec_466x368.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I wonder if they will have turntables in the clink for you to use?</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Auto Dealers Back Online - I&#8217;m Left With Questions</h2><p><strong><a href="https://www.cnn.com/2024/07/11/business/cdk-hack-ransom-tweny-five-million-dollars/index.html">How did the auto dealer outage end? CDK almost certainly paid a $25 million ransom</a> (CNN)</strong></p><p>There&#8217;s a lot to unpack in this story. According to the article on CNN, auto dealership software company CDK Global appears to have paid a $25M ransom to get their systems and dealer networks back online. On June 21st, a roughly $25M crypto payment was tracked as delivered to what is believed to be the ransomware group &#8220;BlackSuit,&#8221; but neither the sender nor the target of the money can be confirmed at this time. As I read the article, I was left with three questions that maybe my readers can help me with:</p><ol><li><p><em><strong>How do companies actually go about PAYING a ransom like this?</strong></em> I can&#8217;t imagine that CDK Global had the technical chops in-house to figure out how to pay $25M in crypto to get their systems back online &#8212; they most likely had to have used a third-party service to deliver the payment. Who offers this type of service, and how much money do THEY make on the deal?! Wow, this is most definitely a morally grey area product offering.</p></li><li><p>$25M is a LOT of money. <em><strong>My initial concern was how does a global auto dealership software vertical SaaS offering like CDK Global have $25M lying around.</strong></em> Apparently, they are much larger than I thought!  CDK Global was acquired in April 2022 for over $8B, and the parent holding company, Brookfield Business Partners, is MASSIVE. But what if they DIDN&#8217;T have it available - where do they go to get the money (gov? insurance?), and if they can&#8217;t get it liquid, do they just POOF out of business?</p></li><li><p><em><strong>With over $1.1B in ransomware payments occurring last year, how concerned are we that this will grow in the future?</strong></em> I&#8217;ve seen tons of different incentive structures for hackers over the last 20+ years but this one shares the SHIT outta me. This is HUGE money, and I don&#8217;t see how attackers will ever move off of this approach if they can extort such massive financial windfalls. I only see this getting worse in the next year or two. What are your thoughts - can we limit ransomware? If so, how, when, and what will finally help us lower the risk?</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Stolen Legos Worth Over $200K Recovered</h2><p><strong><a href="https://www.nbcnews.com/news/us-news/oregon-police-recover-200000-lego-sets-massive-bust-rcna161275?_hsenc=p2ANqtz-8cf-TQWGzdnbDcXsT6nkr9YuHaRdrf1pUfRnbv7NMZwauXIc9B6jZnjPOSyUHKQVfTBXfktrYvK6xk5kyqWeW5RLBV7g&amp;_hsmi=315435673">Oregon police recover over $200,000 worth of Lego sets in massive bust</a> (NBC News)</strong></p><p>Legos are a big deal. I&#8217;ve always been a fan of Lego. Since I was a little kid and got my first set, I have collected, assembled, and destroyed more Lego objects than I care to admit. What I never really understood is the collectible nature of the damn things. I mean, all they are is bricks and a book that tells you how to put them all together. So simple.. yet so amazing. Apparently, Lego has turned into a big business, and these criminals figured it out. Throughout a three-month investigation, Oregon police built a case against a store owner who had been &#8220;knowingly purchasing stolen sets&#8221; of Lego. The total value of the recovered Lego sets was over $200K. I should have kept all those bins from back in the day&#8230; instead, they are in the local dump alongside my baseball cards and old Beanie Babies. C&#8217;est la vie!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w3WE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w3WE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 424w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 848w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 1272w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w3WE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif" width="530" height="444.3482142857143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:939,&quot;width&quot;:1120,&quot;resizeWidth&quot;:530,&quot;bytes&quot;:157885,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w3WE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 424w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 848w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 1272w, https://substackcdn.com/image/fetch/$s_!w3WE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f531e39-ff42-424d-a15e-fdf8e842c9cd_1120x939.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>SaaS Must Adapt To Survive</h2><p><strong><a href="https://tomtunguz.com/ai-copilot-premium-pricing/">AI Pricing Strategies for SaaS Companies Offering Copilots </a>(Tomasz Tunguz)<br><a href="https://tomtunguz.com/ai-agent-pricing/">No SaaS! How AI Agents Will Change Software Pricing</a> (Tomasz Tunguz)<br><a href="https://docsend.com/view/5hk8prddivq54nne">Avenir x SaaS - What&#8217;s Gone Wrong in Software and Why We&#8217;re Optimistic</a> (Avenir)<br></strong><a href="https://nextbigteng.substack.com/p/is-saas-dead">SaaS: Have reports of my death been greatly exaggerated?</a> (Next Big Teng)</p><p><em><strong>Warning - This is a LONG ONE.. I went full nerd on this post.</strong></em></p><p>Lately, I&#8217;ve been pondering the idea that we may have seen the height of the software-as-a-service (SaaS) approach to business and are facing the next wave of foundational change. How will AI impact business, and in particular, will SaaS as an offering die over time?</p><p>The research conducted by Avenir in their slide deck entitled &#8220;<a href="https://docsend.com/view/5hk8prddivq54nne">What&#8217;s Gone Wrong in Software and Why We&#8217;re Optimistic</a>&#8221; examines the impact of COVID on SaaS solutions, positing that the pandemic has catapulted SaaS business models straight through adolescence and directly into maturity. We&#8217;re seeing this in nearly all metrics around high-growth software-based companies in this cohort. Revenue growth has slowed, and by force, these companies must become more efficient in order to maintain any level of foundational financial success. The best quote in the article is, &#8220;What management teams have referred to as &#8220;tough macro&#8221; is likely a &#8220;new normal.&#8221;</p><p><em><strong>Prediction: SaaS is already mature and has long passed its days as a growth investment.</strong></em></p><p>Two new posts from Tomasz Tunguz expand on the concept, detailing how AI agents will change pricing models in the software business. According to Tomasz, AI agents are 2.5x-3x more efficient than human counterparts, yet we are only charging an uplift of, on average, 70% against non-AI, traditionally seat-based SaaS solutions today. There is room for price increases, and SaaS companies will likely hop on this trend over the next few years. It&#8217;s why we&#8217;re seeing so much vendor-side investment in AI and copilots - there is a ton of upside if they can increase margins and add AI-based feature sets for their customers to consume.</p><p><em><strong>Prediction: AI will increase prices for tools and technology to run our businesses, matching an offset in human resource requirements.</strong></em></p><p>If companies rationally attempt to solve their SaaS efficiency problems by removing human resources and replacing them with AI-based automation, the result will be a massive increase in AI-based demand and a new wave of business fundamentals away from SaaS and into SaaS-enabled AI agent-driven automation. This will change how we tactically operate day to day, how we are charged for our products and services, and how businesses manage themselves to meet the new market needs.</p><p><em><strong>Prediction: Over time, SaaS decreases in value in favor of AI-based systems potentially delivered in a SaaS model, but more likely via some type of new interface will overtake the SaaS UI.</strong></em></p><p>AI will drastically change how software is written, consumed, and charged for and, in time, completely rewrite how software businesses are run. Just as software was a massive paradigm shift that took a decade or more to understand, AI is on the same trajectory. I know this was a nerdy post, but thanks for bearing with me. I encourage you to read all three pieces and clap back at me with healthy debate and discussion. See you in the comments!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/wwrtw-071324?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/wwrtw-071324?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>These Shoes Were Made For (VR) Walking!</h2><p><strong><a href="https://www.freeaim.com/">Freeaim VR Shoes</a> (Freeaim)</strong></p><p>For our Story #5 this week, we bring you - Freeaim VR Shoes! If you don&#8217;t want to overpay for a VR-enabled treadmill designed to allow you to walk in virtual worlds, you can instead spring for brand-new virtual reality shoes! They may not look like the latest Jordans, but they are just as much of a waste of money. These shoes are designed to connect with your VR system to provide you with a fully immersive ability to walk around and not actually GO ANYWHERE! They aren&#8217;t cheap either - the current dev kit is $4999, and they hope to have the final retail version available for around $1000 USD. Just a word of caution: the &#8220;Swivel Caster Frame&#8221; is not included, and they have yet to figure out how to allow you to walk backward. Buyer beware!</p><div id="youtube2-1Rk67PPff6M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;1Rk67PPff6M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/1Rk67PPff6M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.cnn.com/2024/07/08/travel/barcelona-tourism-protests-scli-intl/index.html">Barcelona anti-tourism protesters fire water pistols at visitors</a> (CNN) - </strong>First, it won&#8217;t work. Second, it&#8217;s just stupid. Why are you bothering them?</p></li><li><p><strong><a href="https://abcnews.go.com/US/att-hacker-stole-data-wireless-customers/story?id=111874118">AT&amp;T says hacker stole some data from 'nearly all' wireless customers</a> (ABC News)</strong> - They stole all the things.. ALL OF EM! Yet another massive breach.</p></li><li><p><strong><a href="https://cybernews.com/news/ticketmaster-notifies-customers-omits-important-details/">Ticketmaster finally notifies customers, omits important details </a>(Cybernews)</strong> - We knew about this one for a while. More massive breaches going down.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (7/5/24)]]></description><link>https://www.thecyberwhy.com/p/tcw-07052024</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw-07052024</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 05 Jul 2024 16:28:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2c49a3-8fe0-4d5f-8d99-bd28b84924b0_1080x1920.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Happy &#8220;try not to explode your fingers&#8221; week!</strong> That&#8217;s right, it&#8217;s the fourth of July and The Cyber Why is here to bring you all the cyber news that will &#8220;blow&#8221; your mind! This week the <a href="http://thecyberwhy.com">TCW</a> crew reminisces about the first time we saw a web browser, discusses how GTM in cyber is different, generative AI breaks reality, Cloudflare gives the finger to AI crawlers, and a wake boarding beer drinking gem from the great Zuck! All this and more in this week&#8217;s <a href="http://thecyberwhy.com">The Cyber Why!</a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong><a href="https://www.thecyberwhy.com/podcast">The Cyber Why POD - Now in 4k!</a> (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong><a href="http://thecyberwhy.com">TCW Newsletter </a>and the <a href="https://www.thecyberwhy.com/podcast">TCW Podcast</a> both have a few 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Marc Andreessen said he loves The Cyber Why. You should subscribe too!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Marc Andreessen and the History of Netscape</h2><p><strong><a href="https://pmarca.substack.com/p/the-true-story-as-best-i-can-remember">The true story -- as best I can remember -- of the origin of Mosaic and Netscape</a> (Marc Andreessen Substack)</strong></p><p>I&#8217;m a sucker for historical content. I love documentaries, historical data analysis, and learning about the past to help us with the future. I specifically remember the first time I saw a &#8220;web browser&#8221;. It was the Mosaic browser on a Sun SPARC Station in 1993. I was freshman at the <a href="http://rit.edu">Rochester Institute of Technology</a> and one of my classmates loaded up Mosaic to introduce me to the &#8220;World Wide Web&#8221;. I was simultaneously amazed and bored. It was super cool to have interesting data at your fingers tips yet a total waste of time because it was impossible to find anything of real value (this was pre search engines). Essentially it felt a lot like ChatGPT does today! If you are into the history of the Internet, check out this great content on the &#8220;true story of the origin of Mosaic and Netscape.&#8221;</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:146090503,&quot;url&quot;:&quot;https://pmarca.substack.com/p/the-true-story-as-best-i-can-remember&quot;,&quot;publication_id&quot;:1434963,&quot;publication_name&quot;:&quot;Marc Andreessen Substack&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ef02fe-d089-466f-9b4a-ea19df828473_400x400.jpeg&quot;,&quot;title&quot;:&quot;The true story -- as best I can remember -- of the origin of Mosaic and Netscape.&quot;,&quot;truncated_body_text&quot;:&quot;&quot;,&quot;date&quot;:&quot;2024-06-28T20:13:43.134Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:22353,&quot;name&quot;:&quot;Marc Andreessen&quot;,&quot;handle&quot;:&quot;pmarca&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8ef02fe-d089-466f-9b4a-ea19df828473_400x400.jpeg&quot;,&quot;bio&quot;:&quot;Powerful person; can&#8217;t handle being questioned.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-05-19T00:15:36.212Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:1398366,&quot;user_id&quot;:22353,&quot;publication_id&quot;:1434963,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:1434963,&quot;name&quot;:&quot;Marc Andreessen Substack&quot;,&quot;subdomain&quot;:&quot;pmarca&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;My personal Substack.\nPersonal views only.\nActually, not even personal views.\nI don't even know what my personal views are anymore.\nIt doesn't matter.\nRead anyway!&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8ef02fe-d089-466f-9b4a-ea19df828473_400x400.jpeg&quot;,&quot;author_id&quot;:22353,&quot;theme_var_background_pop&quot;:&quot;#EA410B&quot;,&quot;created_at&quot;:&quot;2023-02-20T19:36:55.606Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;Marc Andreessen Substack&quot;,&quot;copyright&quot;:&quot;Marc Andreessen&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:false,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;is_personal_mode&quot;:false}}],&quot;twitter_screen_name&quot;:&quot;pmarca&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;podcast&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://pmarca.substack.com/p/the-true-story-as-best-i-can-remember?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!zpuu!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ef02fe-d089-466f-9b4a-ea19df828473_400x400.jpeg" loading="lazy"><span class="embedded-post-publication-name">Marc Andreessen Substack</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title-icon"><svg width="19" height="19" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
  <path d="M3 18V12C3 9.61305 3.94821 7.32387 5.63604 5.63604C7.32387 3.94821 9.61305 3 12 3C14.3869 3 16.6761 3.94821 18.364 5.63604C20.0518 7.32387 21 9.61305 21 12V18" stroke-linecap="round" stroke-linejoin="round"></path>
  <path d="M21 19C21 19.5304 20.7893 20.0391 20.4142 20.4142C20.0391 20.7893 19.5304 21 19 21H18C17.4696 21 16.9609 20.7893 16.5858 20.4142C16.2107 20.0391 16 19.5304 16 19V16C16 15.4696 16.2107 14.9609 16.5858 14.5858C16.9609 14.2107 17.4696 14 18 14H21V19ZM3 19C3 19.5304 3.21071 20.0391 3.58579 20.4142C3.96086 20.7893 4.46957 21 5 21H6C6.53043 21 7.03914 20.7893 7.41421 20.4142C7.78929 20.0391 8 19.5304 8 19V16C8 15.4696 7.78929 14.9609 7.41421 14.5858C7.03914 14.2107 6.53043 14 6 14H3V19Z" stroke-linecap="round" stroke-linejoin="round"></path>
</svg></div><div class="embedded-post-title">The true story -- as best I can remember -- of the origin of Mosaic and Netscape.</div></div><div class="embedded-post-cta-wrapper"><div class="embedded-post-cta-icon"><svg width="32" height="32" viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg">
  <path classname="inner-triangle" d="M10 8L16 12L10 16V8Z" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"></path>
</svg></div><span class="embedded-post-cta">Listen now</span></div><div class="embedded-post-meta">2 years ago &#183; Marc Andreessen</div></a></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Go To Market in Cyber is Just DIFFERENT!</h2><p><strong><a href="https://ventureinsecurity.net/p/cybersecurity-technology-adoption">Cybersecurity technology adoption cycle and its implications for startups and security teams</a> (Venture In Security)</strong></p><p>Another excellent article from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ross Haleliuk&quot;,&quot;id&quot;:2607604,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa0e73b-27de-49eb-a585-393f1add9ab8_1500x1000.jpeg&quot;,&quot;uuid&quot;:&quot;731b467e-9c94-42e9-a932-e36152378231&quot;}" data-component-name="MentionToDOM"></span> from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Venture in Security&quot;,&quot;id&quot;:746596,&quot;type&quot;:&quot;pub&quot;,&quot;url&quot;:&quot;https://open.substack.com/pub/ventureinsecurity&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86fcb772-b0a3-43e4-ab8c-33c6bfa2378f_1181x1181.png&quot;,&quot;uuid&quot;:&quot;b058b76e-7334-44fd-9c7e-9f1d24d30f91&quot;}" data-component-name="MentionToDOM"></span>. This time with the help of <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Kane Narraway&quot;,&quot;id&quot;:250392552,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cf55d6b-cd6c-427c-85d2-54831c95fc66_839x994.png&quot;,&quot;uuid&quot;:&quot;0ca7fd10-b276-4612-a2a4-9d20943a17a6&quot;}" data-component-name="MentionToDOM"></span>, Ross breaks down the cybersecurity adoption cycle and how it is reversed from the more common model as seen in non-cyber markets. Ross and Kane are right on with their analysis, specifically helping security teams understand how the dynamics of emerging technologies should work in their organization and what it really takes to be a design partner of innovative companies and technologies. They take a very buyer-centric view into the adoption cycle giving direct guidance on how security teams can mature over time.</p><p>I have seen this model from the other side of the coin for over a two decades. As an early go to market executive at both Signal Sciences and JupiterOne, I saw the vendor side of their framework play out. Early adopters of both companies were the highly mature security programs that had security engineering teams and the ability to take raw technology and mold it to their requirements. As the products we were building became more feature complete we were able to move downward to the design partner and early adopter segments of the curve. Generally this meant breaking open the finance and banking verticals. Finally, the hardest group to sell to was what I called the &#8220;mass buyer.&#8221; This buyer was almost always way less advanced in their cyber program and needed a specific set of features to make the technology usable to their low resourced and limited skill sets teams. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kFQq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kFQq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 424w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 848w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 1272w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kFQq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png" width="588" height="391.7307692307692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:588,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kFQq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 424w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 848w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 1272w, https://substackcdn.com/image/fetch/$s_!kFQq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F446869ac-25ac-4d46-bdf6-e34115db466d_1600x1066.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a great article to read and comprehend for both cybersecurity buyers as well as those companies looking to build a go to market engine.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Could Generative AI Break Reality - YES!</h2><p><strong><a href="https://www.404media.co/email/dd4acda7-3cf5-48a1-a940-8bdf0aede2b4/">Google Says AI Could Break Reality</a> (404 Media)<br><a href="https://arxiv.org/pdf/2406.13843">Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data</a> (ARXIV.org)</strong></p><p>A new paper written by a combination of research team members from Google&#8217;s multiple labs reviewed over 200 incidents of genAI misuse between January 2023 and March of 2024. The results of the research indicate that the majority of attacks against generative AI are not technically &#8220;hacks&#8221; of the system itself, but instead are much more focused on abusing the features that exist for malicious behavior or alternative methods of reward. The analysis shows that the prevalence of misuse tactics center on impersonation, scaling and amplification of malicious content, falsification of data, and sockpuppeting. The team at 404 Media did a great job breaking down where the gaps exist in the research (small n, classification issues, etc) but at the end of the day they (and I) are fairly confident that the recommendations and findings are directionally accurate. If these types of attacks continue to propagate unabated, the concept of what &#8220;reality really is&#8221; can indeed morph, or at least be skewed, in order to achieve the attackers intent. It&#8217;s not about attacking the LLM, or input injection, or poisoning the AI data set - it&#8217;s really about abusing the general input and output content in enough volume to make an alternative reality become the norm. <em><strong>How&#8217;s that for some real matrix style shit!</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v_qC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v_qC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 424w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 848w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 1272w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v_qC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png" width="1191" height="892" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:892,&quot;width&quot;:1191,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v_qC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 424w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 848w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 1272w, https://substackcdn.com/image/fetch/$s_!v_qC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb36a2ba-5449-48c3-a1a9-3f2e9c99d6ed_1191x892.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Cloudflare Shoots Across the Bow of AI Crawlers</h2><p><strong><a href="https://www.windowscentral.com/microsoft/cloudflare-goes-to-war-with-microsoft-google-and-openais-bots-with-blanket-free-tools-to-block-all-crawlers">Cloudflare goes to war with Microsoft, Google, and OpenAI's bots, with blanket free tools to block all crawlers</a> (Windows Central)</strong></p><p>Keeping with the theme of &#8220;independence,&#8221; Cloudflare just released a free tool to help content creators declare &#8220;<a href="https://twitter.com/Cloudflare/status/1808486101813760208">AIdependence</a>.&#8221; (<em>OK, first of all the pun doesn&#8217;t even make sense. It was definitely forced.. #fail++.)</em> The technology launch comes on the back of the Microsoft AI chief last week saying that <a href="https://www.windowscentral.com/software-apps/ever-put-content-on-the-web-microsoft-says-that-its-okay-for-them-to-steal-it-because-its-freeware">&#8220;public content on the open web is freeeware.&#8221;</a> In response, Cloudflare created new features that allow customers, even those on the free tier, to block their content from all AI crawlers and bots.</p><p>I&#8217;m struggling with this concept. As a content creator myself, isn&#8217;t the whole point of writing to have a human being consume the output? In the new world, driven by AI systems, the concept of readers doing traditional Google searches for your content will fade away. Instead of going direct to the source pages readers will consume the bulk of their content from some type of aggregation algorithm that is AI derived. It&#8217;s already happening with short form video content via the TikTok and YouTube short systems. As an author, if I want my writing to continue to be discovered I have to let the search systems of the 21st century (AI system crawlers) find my content. Isn&#8217;t this somewhat like telling Google to not index your content back in 1999. It may have felt like the right thing to do at the time but the end result would have been your content never being consumed by an audience. I believe this is what will happen here.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw-07052024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw-07052024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Check it out - I didn&#8217;t spill a DROP!</h2><p><strong><a href="https://www.sfgate.com/renotahoe/article/mark-zuckerberg-lake-tahoe-american-flag-tuxedo-19555381.php">Mark Zuckerberg's Lake Tahoe antics are getting even weirder </a>(SFGate.com)</strong></p><p>To end this edition of The Cyber Why newsletter here&#8217;s something completely unexpected. The all powerful Zuck decided it would be social media worthy to don a tuxedo and an American flag and go wake boarding to the best 4th of July song in history - Born in the USA. This is a very high scoring frat boy activity. Zuck only lost points because he clearly didn&#8217;t properly utter the words &#8220;Hold my beer!&#8221; before he hopped on the board. Hats off to you Zuck - may all of your beers be a banquet!</p><div id="tiktok-iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd" class="tiktok-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://www.tiktok.com/@dailymail/video/7387826133183548714&quot;,&quot;title&quot;:&quot;Mark Zuckerberg went all out for July 4th, wakeboarding in a tuxedo while drinking a beer and waving an American flag. &#129413; #fourthofjuly #independenceday #markzuckerberg #july4 #happy4thofjuly #4dejulio &quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a2c49a3-8fe0-4d5f-8d99-bd28b84924b0_1080x1920.jpeg&quot;,&quot;author&quot;:&quot;Daily Mail&quot;,&quot;embed_url&quot;:&quot;https://cdn.iframe.ly/api/iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd&quot;,&quot;author_url&quot;:&quot;https://www.tiktok.com/@dailymail&quot;,&quot;belowTheFold&quot;:true}" data-component-name="TikTokCreateTikTokEmbed"><iframe id="iframe-tiktok-iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd" class="tiktok-iframe" src="https://cdn.iframe.ly/api/iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd" frameborder="0" allow="autoplay; fullscreen; encrypted-media" allowfullscreen="" scrolling="no" loading="lazy"></iframe><iframe src="https://team-hosted-public.s3.amazonaws.com/set-then-check-cookie.html" id="third-party-iframe-tiktok-iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd" class="third-party-cookie-check-iframe" style="display: none;" loading="lazy"></iframe><div class="tiktok-wrap static" data-component-name="TikTokCreateStaticTikTokEmbed"><a href="https://www.tiktok.com/@dailymail/video/7387826133183548714" target="_blank"><img class="tiktok thumbnail" src="https://substackcdn.com/image/fetch/$s_!Nuxp!,w_640,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2c49a3-8fe0-4d5f-8d99-bd28b84924b0_1080x1920.jpeg" style="background-image: url(https://substackcdn.com/image/fetch/$s_!Nuxp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2c49a3-8fe0-4d5f-8d99-bd28b84924b0_1080x1920.jpeg);" loading="lazy"></a><div class="content"><a class="author" href="https://www.tiktok.com/@dailymail" target="_blank">@dailymail</a><a class="title" href="https://www.tiktok.com/@dailymail/video/7387826133183548714" target="_blank">Mark Zuckerberg went all out for July 4th, wakeboarding in a tuxedo while drinking a beer and waving an American flag. &#129413; #fourthofjuly #independenceday #markzuckerberg #july4 #happy4thofjuly #4dejulio </a></div></div><div class="fallback-failure" id="fallback-failure-tiktok-iframe?media=1&amp;app=1&amp;url=https%3A%2F%2Fwww.tiktok.com%2F%40dailymail%2Fvideo%2F7387826133183548714%3Flang%3Den&amp;key=e27c740634285c9ddc20db64f73358dd"><div class="error-content"><img class="error-icon" src="https://substackcdn.com//img/alert-circle.svg" loading="lazy">Tiktok failed to load.<br><br>Enable 3rd party cookies or use another browser</div></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://x.com/deedydas/status/1808188513512575179">Gymnastics is the Turing test of video generation models</a> (<a href="http://x.com/deeydas">@deedydas</a>) - </strong>This could have easily been a story #5. Apparently Gemini classifies this as sexual explicit material as well!</p></li><li><p><strong><a href="https://www.businessinsider.com/abnormal-security-valued-at-5-billion-in-new-funding-round-2024-6">AI startup Abnormal Security is set to be valued at $5 billion in new funding round, sources say</a> (Business Insider) - </strong>That&#8217;s a LOT of cheddar. The pace of that treadmill just jumped another few miles per hour. Keep running hard Abnormal!</p></li><li><p><strong><a href="https://www.linkedin.com/pulse/6-things-know-getting-acquired-good-bad-somewhat-ugly-jason-m-lemkin-xvpoc/">6 Things To Know About Getting Acquired: The Good, The Bad, The Somewhat Ugly</a> (Jason M. Lemkin) - </strong>I have been giving similar tips to founders for years. These are things many first time founders don&#8217;t know about M&amp;A.</p></li><li><p><strong><a href="https://matduggan.com/a-eulogy-for-devops/">A Eulogy for DevOps</a> (Mathew Duggan) - </strong>An interesting tear down of DevOps explaining why it was doomed to fail from the get go. Comment below!</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!</em></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (6/29/24)]]></description><link>https://www.thecyberwhy.com/p/tcw062924</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw062924</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sat, 29 Jun 2024 18:26:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Happy Saturday. As I sit here putting the final touches on the current TCW newsletter I realize how thankful I am to have friends that help me write the content every week. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Rick Holland&quot;,&quot;id&quot;:118506252,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d26b59c-e2e3-4a81-b2c3-15c3ee1728b2_600x600.jpeg&quot;,&quot;uuid&quot;:&quot;803d079a-16d2-43ec-8b08-1a01e479b010&quot;}" data-component-name="MentionToDOM"></span> <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Katie Teitler-Santullo&quot;,&quot;id&quot;:97046843,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bdfed7-e091-46a7-8607-aac6ce2f7346_250x250.png&quot;,&quot;uuid&quot;:&quot;290919da-deaa-4fb6-884a-d2b87653d113&quot;}" data-component-name="MentionToDOM"></span> <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4ac0fb06-ca31-4031-b771-baf3ec53bd46_679x679.jpeg&quot;,&quot;uuid&quot;:&quot;94506557-3139-4833-8189-f16f2a39def0&quot;}" data-component-name="MentionToDOM"></span> are the best in the biz and I love you guys!</p><p>Now on to this week&#8217;s TCW! This week we cover quant vs. human based venture investing, the polarizing story of Jacob Appelbaum, polyfill or poly-fluff?, nation state false flags, and for story #5 McDonald&#8217;s AI ordering SNAFU! </p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>The Cyber Why POD - Now in 4k! (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong>TCW Newsletter and the TCW Podcast both have a few 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Please subscribe and share with your friends. I&#8217;ll buy you a startbucks next time I see you!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Quant vs. Human Based VC - Math vs. Intuition</h2><p><strong><a href="https://www.newsletter.datadrivenvc.io/p/can-we-fully-automate-startup-investing">Can We Fully Automate Startup Investing?</a> (Data Driven VC)</strong></p><p>Venture investing today is, operationally, drastically different depending on the stage, focus, fund size, and type of investing that you are doing. In the early stages of venture investing there is very little data to go on, making team and idea the predominant factors on which decisions are made. As you progress into later stage investing with companies who have been around a while and have sufficient metrics to analyze, venture investing becomes much more quantifiable. The question that remains is can we apply more quant techniques earlier in the target company lifecycle to make even more data driven decisions in the angel, seed, and pre-seed rounds. Data Driven VC author, Andre Retterath believes the early stage end state will be a blending of quant and human decision making processes which is a cop out if you ask me. If you are an investor, leave your comments below on which methodology will come to dominate early stage over time.</p><blockquote><p><strong>Handcraft / Traditional VC:</strong> A shrinking group of senior, gray-hair industry veterans, characterized by a strong belief that VC is more art than science and that the best deals will always be sourced through their proprietary personal networks. Moreover, they are rarely aware of their biases (recency, similarity, confirmation, over-simplification, etc.) when making decisions and tend to overestimate their position based on their firm and personal brands as well as their (oftentimes impressive) investment track records.</p><p><strong>Augmented VC:</strong> Combining the best of both worlds, where machines collect, process and contextualize vast amounts of data to achieve comprehensive coverage and give direction, and where human investors focus on a select number of founders to build deep relationships and assess the soft factors based on their intuition. While data provides coverage and guidance, the human makes the final decision.</p><p><strong>Quant VC:</strong> A new species of purebred algorithmic VCs who believe that startup investment decisions should not involve humans at all, just like in pure-play quant public funds. Just algos, no humans. Fast, clean and repeatable. These investors believe that human involvement skews the models and reduces the likelihood to generate alpha.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>ioerror - The Story of a Polarizing Figure</h2><p><strong><a href="https://www.cbc.ca/documentaries/this-cyber-security-activist-made-me-afraid-of-surveillance-culture-1.7223883">This cyber-security activist made me afraid of surveillance culture</a> (CBC)<br><a href="https://gem.cbc.ca/nobody-wants-to-talk-about-jacob-appelbaum?autoplay=1">Nobody Wants To Talk about Jacob Appelbaum Movie </a>(CBC)</strong></p><p>Jacob Appelbaum. AKA ioerror. I remember him from Defcon and Blackhat in the early to mid-2000s. He had white hair and a bit of a wild and crazy demeanor. We ran in similar circles, yet he always had something off about him. My spidey senses tingled, and I distanced myself from him quickly. At the time, I wasn&#8217;t sure what bothered me other than something wasn&#8217;t right. </p><p>I won&#8217;t use this platform to dive into his history or past&#8212;you can research that independently. The short of his story is this: He supposedly contributed to some very interesting cyber research in the mid-2000s. Behind closed doors, he was often referred to as a &#8220;hanger-on&#8221; and a &#8220;noncontributor&#8221; by the other authors of the papers. At the end of the day, none of the technical work mattered when compared to the horrible accusations and proven actions that surfaced.  Eventually, he connected with Julian Assange, WikiLeaks, and the Tor Foundation, and everything went completely off the rails from there. Nobody is sure if the core of the story is one of paranoia and mental issues or, indeed, a government plot to wreck a person&#8217;s life (or maybe a bit of both.) Either way, I&#8217;m watching this movie this weekend!</p><p>The new documentary entitled &#8220;Nobody Wants To Talk About Jacob Appelbaum&#8221; by director and creator Jasmie Kastner is <a href="https://gem.cbc.ca/nobody-wants-to-talk-about-jacob-appelbaum?autoplay=1">available free on CBC</a>. </p><div id="youtube2--y0q2rOkOOc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;-y0q2rOkOOc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/-y0q2rOkOOc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Polyfill or Poly-fluff?</h2><p><strong><a href="https://thehackernews.com/2024/06/over-110000-websites-affected-by.html">Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain Attack</a> (The Hacker News)<br><a href="https://dev.to/snyk/polyfill-supply-chain-attack-embeds-malware-in-javascript-cdn-assets-55d6">Polyfill supply chain attack embeds malware in JavaScript CDN assets</a></strong><a href="https://dev.to/snyk/polyfill-supply-chain-attack-embeds-malware-in-javascript-cdn-assets-55d6"> </a><strong>(Dev.to)<br><a href="https://www.darkreading.com/remote-workforce/polyfillio-supply-chain-attack-smacks-down-100k-websites">Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites </a>(Dark Reading)<br><a href="https://www.pcmag.com/news/hulu-100k-websites-may-be-exposed-javascript-polyfill-domain-malware">Hulu, 100K+ Websites May Be Exposed to Polyfill Malware </a>(PC Mag)</strong></p><p><strong>(</strong><em><strong>Katie pick</strong></em><strong>)</strong> Earlier this week it was reported that polyfill.io, a widely used JavaScript service, was compromised, potentially impacting 100,000+ websites. As the news rolled out, watchers speculated on whether the service&#8217;s new China-based content delivery network (CDN) company, Funnull, had anything to do with the exploit, either intentionally or unintentionally.</p><p>The timing was suspicious: Funnull took ownership of the domain; shortly thereafter, malicious code was delivered through any website using cdn.polyfill.io, redirecting users to betting and porn websites. No reports of  anything more than redirects have been issued.</p><p>Curiously, Polyfill&#8217;s original creator, Andrew Betts, warned people back in February when the domain was sold to the Chinese entity. He noted that &#8220;no website today requires any of the polyfills in the polyfill.io library.&#8221;</p><p>Well, I guess some companies didn&#8217;t hear/read the statement or didn&#8217;t care. But the story doesn&#8217;t end there: As of Thursday, Namecheap.com, a domain hosting company, decided to remove polyfill.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OA7Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OA7Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 424w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 848w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 1272w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OA7Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png" width="472" height="462.52842809364546" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1172,&quot;width&quot;:1196,&quot;resizeWidth&quot;:472,&quot;bytes&quot;:457771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OA7Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 424w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 848w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 1272w, https://substackcdn.com/image/fetch/$s_!OA7Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba74074-0110-4c6b-b6c4-7f9cfd3e5c3a_1196x1172.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In theory, this stops any further propagation of the attack. Time will tell.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Nation States Deploying Ransomware To Throw Defenders Off The Scent</h2><p><strong><a href="https://www.darkreading.com/ics-ot-security/china-nexus-group-using-ransomware-to-disguise-cyber-espionage-activities">ChamelGang APT Disguises Espionage Activities With Ransomware </a>(Dark Reading)<br><a href="https://www.infosecurity-magazine.com/news/chinese-state-ransomware-conceal">Chinese State Actors Use Ransomware to Conceal Real Intent</a> (InfoSecurity Magazine)<br><a href="https://www.sentinelone.com/labs/chamelgang-attacking-critical-infrastructure-with-ransomware/">Cyberespionage Groups Attacking Critical Infrastructure with Ransomware </a>(Sentinel One Labs)</strong></p><p><strong>(</strong><em><strong>Rick pick</strong></em><strong>)</strong> This week, SentinelOne's SentinelLabs released new research highlighting suspected Chinese and North Korean APT groups leveraging ransomware in their campaigns for &#8220;financial gain, disruption, distraction, misattribution, or removal of evidence.&#8221; In traditional intelligence parlance, the misattribution angle is referred to as a false flag. If you aren't a spymaster or Jason Bourne, let me help you out. The <a href="https://www.cia.gov/resources/spy-glossary/">CIA defines</a> a false flag as a:</p><blockquote><p>"deliberate misrepresentation of motives or identity; an operation designed to appear as if it were conducted by someone other than the person or group responsible for it." </p></blockquote><p>APT groups gain plausible deniability from conducting ransomware activity, and data exfiltration is part of the IP theft playbook. When conducting investigations, don&#8217;t make attribution assumptions. If you are in the US manufacturing sector in particular, you should read the full report and conduct threat hunting on the research findings.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw062924?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw062924?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Bacon Ice Cream Should Be A Feature, Not An AI Misfire</h2><p><strong><a href="https://www.bbc.com/news/articles/c722gne7qngo">Bacon ice cream and nugget overload sees misfiring McDonald's AI withdrawn </a>(BBC)<br><a href="https://nypost.com/2024/06/17/business/mcdonalds-to-end-ai-drive-thru-experiment-after-errant-orders/">McDonald&#8217;s to end AI drive-thru experiment after errant orders &#8212; including bacon on ice cream and $222 McNuggets bill</a> (New York Post)</strong></p><p>AI is everywhere, even McDonalds. About a year ago McDonalds restaurant group rolled out AI based chatbot ordering to over 100 stores nation wide. The result of the year long experiment has been colossal failure and a horrible inability to take accurate orders. Viral videos have emerged showing hundreds of dollars of chicken nuggets sneaking onto the order slip, dozens of cream and kethup packets being added to a drive through request, and even one person getting a side of bacon layered on top of her ice cream cup. What a mess up - at least learened that current AI capabilities aren&#8217;t quite ready to ask if you would like fries with that!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uMoS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uMoS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uMoS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg" width="336" height="504" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1800,&quot;width&quot;:1200,&quot;resizeWidth&quot;:336,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Maple Bacon Crunch Ice Cream Recipe&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Maple Bacon Crunch Ice Cream Recipe" title="Maple Bacon Crunch Ice Cream Recipe" srcset="https://substackcdn.com/image/fetch/$s_!uMoS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uMoS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5a47b73-94e2-4a4a-970c-da35a94ad079_1200x1800.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I have to admit it - this looks freaking GOOD!</figcaption></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.bleepingcomputer.com/news/security/neiman-marcus-confirms-data-breach-after-snowflake-account-hack/">Neiman Marcus confirms data breach after Snowflake account hack</a> (Bleeping Computer) - </strong>The long tail of the exposed Snowflake credentials continues.</p></li><li><p><strong><a href="https://www.bleepingcomputer.com/news/security/teamviewers-corporate-network-was-breached-in-alleged-apt-hack/">TeamViewer's corporate network was breached in alleged APT hack</a> (Bleeping Computer)</strong> <strong>- </strong>Russian threat actor, APT29 is actively exploiting the popular remote access solution.</p></li><li><p><strong><a href="https://www.theregister.com/2024/06/26/batten_down_the_hatches_its/">Batten down the hatches, it's time to patch some more MOVEit bugs </a>(The Register)</strong> - Progress Software is making headlines for all the wrong reasons, again.</p></li><li><p><strong><a href="https://www.securityweek.com/evolve-bank-data-leaked-after-lockbits-federal-reserve-hack/">Evolve Bank Data Leaked After LockBit&#8217;s &#8216;Federal Reserve Hack&#8217;</a> (Security Week)</strong> - LockBit claimed to have 33 TB of Federal Reserve data, but so far it appears to be from an Arkansas bank.</p></li><li><p><strong><a href="https://www.reuters.com/technology/cybersecurity/blacksuit-hacker-behind-cdk-global-attack-hitting-us-car-dealers-2024-06-27/">The 'BlackSuit' hacker behind the CDK Global attack hitting US car dealers </a>(Reuters)</strong> - Reuters took a deeper dive into the ransomware actor behind the CDK Global outage crippling car dealerships across the country.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (6/24/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-94f</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-94f</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Mon, 24 Jun 2024 13:58:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you haven&#8217;t checked out The Cyber Why Podcast <a href="https://www.thecyberwhy.com/podcast">CLICK HERE</a>! The monthly(ish) podcast covers the latest cyber news, commentary, debate, and discussion with a bit of fun and flare. You can find TCW Pod on <a href="http://thecyberwhy.com/podcast">thecyberwhy.com</a> and all of your favorite podcast streaming systems.</p><p>This week in The Cyber Why Newsletter we cover a great article from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ross Haleliuk&quot;,&quot;id&quot;:2607604,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa0e73b-27de-49eb-a585-393f1add9ab8_1500x1000.jpeg&quot;,&quot;uuid&quot;:&quot;df13c0b7-1193-4927-92bd-22f7c7d54410&quot;}" data-component-name="MentionToDOM"></span> on hiring for a startup vs an established org, more details emerge on Shinyhunters and Snowflake, Kaspersky banned from US operations (and photos of Tyler at a Kaspersky boondoggle), more pork on Pig Butchering style attacks, and an EPIC RANT on AI. All this and more is in this week&#8217;s TCW newsletter.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gUhv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg" width="226" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1400,&quot;width&quot;:1400,&quot;resizeWidth&quot;:226,&quot;bytes&quot;:58729,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gUhv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gUhv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1d58335-126c-41a3-87bd-397523df326f_1400x1400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>The Cyber Why POD - Now in 4k! (</strong>To be fair, it always has been in 4k and high-quality audio. We&#8217;re tech nerds like that.)</p><p><strong>TCW Newsletter and the TCW Podcast both have a few 2024 sponsorship slots remaining!</strong> If you are interested in reaching nearly 5k security-minded people a week via direct mail plus nearly 30K views per month, sponsor The Cyber Why. It&#8217;s inexpensive - I SWEAR! Email tyler.shields@gmail.com for more information.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you don&#8217;t subscribe, Kaspersky will take over the planet! Don&#8217;t let that happen.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Startup Vs. High Growth - Same Thing, Right?</h2><p><strong><a href="https://ventureinsecurity.net/p/hiring-top-performers-from-large">Hiring top performers from large cybersecurity vendors won't help early-stage startups grow, but it can ruin them </a>(Venture In Security)</strong></p><p>I want to open this week&#8217;s TCW newsletter with a top-tier piece by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ross Haleliuk&quot;,&quot;id&quot;:2607604,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa0e73b-27de-49eb-a585-393f1add9ab8_1500x1000.jpeg&quot;,&quot;uuid&quot;:&quot;80916727-487b-430c-9c37-2b9637edf8b1&quot;}" data-component-name="MentionToDOM"></span> from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Venture in Security&quot;,&quot;id&quot;:746596,&quot;type&quot;:&quot;pub&quot;,&quot;url&quot;:&quot;https://open.substack.com/pub/ventureinsecurity&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86fcb772-b0a3-43e4-ab8c-33c6bfa2378f_1181x1181.png&quot;,&quot;uuid&quot;:&quot;b93bdc86-8c36-4d97-ac95-bafe4ce80ec3&quot;}" data-component-name="MentionToDOM"></span>.  The differences between building a startup and scaling a high-growth yet larger company are massive. Forget about the learnings you get going from $50M in ARR to $200M+, the run from $0 to $10 is so different, I would argue that the knowledge you gain from one will not only slow down your efficacy in the other, but there is a very real chance that it will cause you to FAIL when making the switch. Ross does an excellent job detailing exactly why this phenomenon exists and why hiring people from your network who have experience in your growth phase is the best way to build your business. If you are a founder or entrepreneur who has hiring responsibility, this article is an absolute must-read.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Shinyhunters Reveals How They Compromised Snowflake Customers</h2><p><strong><a href="https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/">Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake </a>(WIRED)<br></strong><em><strong>(</strong>Rick pick)</em> Earlier this week, the great <a href="https://www.wired.com/author/kim-zetter/">Kim Zetter</a> scored a text chat interview with Shinyhunters, the threat actor that purportedly compromised Snowflake customers Ticketmaster and Santander. Shinyhunters has been on the cybercriminal scene since <a href="https://www.reliaquest.com/blog/the-eeveelution-of-shinyhunters-from-data-leaks-to-extortions/">May of 2020</a> (full disclosure, link to Rick's day job), where they started selling and giving away data breaches for free. The group transitioned into extortion and continues to make headlines. The big news from the WIRED article is that there is a 4th party risk angle to these incidents. Shinyhunters claimed to have compromised <a href="https://www.epam.com/">EPAM Systems</a>, a Snowflake partner. EPAM discounted Shinyhunter's allegations, saying, "It does not believe that it played a role in the breaches and suggested the hacker had fabricated the tale." Infostealers aren't new, but they are trending, and defenders need a strategy to defend against them. Start with MFA, use passkeys, don't allow syncing personal browsers with work browsers, and set shorter session cookie timeouts. Keep threat actors from using your credentials to gain initial access.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Kaspersky Banned From US Operations</h2><p><strong><a href="https://www.msn.com/en-us/news/world/exclusive-biden-to-ban-us-sales-of-kaspersky-software-over-russia-ties-source-says/ar-BB1oAI9o">Exclusive-Biden to ban US sales of Kaspersky software over Russia ties, source says</a> (Update)<br><a href="https://www.zetter-zeroday.com/new-government-ban-on-kaspersky-would-prevent-malware-signature-updates/?ref=zero-day-newsletter">New Government Ban on Kaspersky Would Prevent Company from Updating Malware Signatures in U.S.</a> (Kim Zetter)<br><a href="https://en.wikipedia.org/wiki/Eugene_Kaspersky">Eugene Kaspersky</a> (Wikipedia Entry)</strong></p><p>Russian antivirus firm Kaspersky has been banned from selling its software in the United States. In addition, they are no longer allowed to provide updates to customers that reside within the US borders. Kaspersky has skirted along the edges of the United States political system for as long as I can remember (see controversies section on Eugene Kaspersky&#8217;s Wikipedia entry <a href="https://en.wikipedia.org/wiki/Eugene_Kaspersky">here</a>). The Department of Homeland Security even banned Kaspersky from all federal US government systems in 2017, citing multiple transgressions. </p><p>When I was a cyber researcher (long ago), Kaspersky held an annual boondoggle where they flew every big-name researcher, market analyst, influencer, and more to a remote location and held a killer cyber conference. After several years off, the event <a href="https://thesascon.com/">recently resurfaced and will be hosted in Bali, Indonesia, in 2024</a>. The event has never been held in the United States - the rumor and prevailing opinion was that over half of the company couldn&#8217;t get into the country to host it here. Somehow, I managed to get invited for my mobile security research during my days as a market analyst. I had so much hair back then!</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f9ce008-7756-4fbe-aabc-43bcf6c02463_4128x2322.jpeg&quot;},{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10d35fd7-a47d-4675-990c-82c530a1005d_4128x2322.jpeg&quot;},{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebb4fdc8-9a7f-4078-ae7b-7d4bf26eba86_1536x1536.jpeg&quot;}],&quot;caption&quot;:&quot;Tyler at Kaspersky Security Analyst Summit 2014&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebb0eedc-ddec-4685-9af4-4c1664a4f050_1456x474.png&quot;}},&quot;isEditorNode&quot;:true}"></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Pig Butchers Are The Worst Type Of Criminal </h2><p><strong><a href="https://www.cnn.com/2024/06/17/asia/pig-butchering-scam-southeast-asia-dst-intl-hnk/index.html">Killed by a scam: A father took his life after losing his savings to international criminal gangs</a> (CNN)<br></strong><em><strong>(</strong>Rick pick)</em> We have covered "pig butchers" in the past; it is a heartbreaking scheme where criminals run a long con on their victims to get them to invest in fraudulent crypto. Often, these romance scams target lonely retired folks and wipe out their life savings and dignity. A country prosecutor quoted in this CNN story said:</p><blockquote><p>"<em>I've been a prosecutor for over 25 years. I've done all kinds of different types of crime. I spent nine years in sexual assault. And I've never seen the absolute decimation of people that I've seen as a result of pig butchering.</em>" </p></blockquote><p>Sadly, many of those who conduct these scams are trafficked to places in Southeast Asia against their will and forced to fleece their victims. I have some personal experience with these types of scams. Although no money was lost, a close family member of mine was actively groomed over months in an attempt to cash out. Some scams focus on crypto investment, while others seek to have money wired overseas. In 2023, the <a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3ElderFraudReport.pdf">FBI Internet Crimes Complaint Center</a> "<em>received reports from 6,740 individuals over the age of 60 who experienced almost $357 million in losses to Confidence/Romance scams.</em>" We must educate our parents and grandparents on the predators that conduct these scams and how to protect themselves. Jason Statham&#8217;s latest film, &#8220;The Beekeeper,&#8221; has him get payback on these types of scammers. Go get &#8216;em JASON!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tGdX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tGdX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 424w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 848w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 1272w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tGdX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png" width="490" height="270.40133779264215" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:660,&quot;width&quot;:1196,&quot;resizeWidth&quot;:490,&quot;bytes&quot;:485492,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tGdX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 424w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 848w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 1272w, https://substackcdn.com/image/fetch/$s_!tGdX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e651ab4-50c3-4351-bf84-a1d92a907319_1196x660.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h6>                                                              </h6><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-94f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-94f?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Rant On My Friend! Epic Rant on AI Hype!</h2><p><strong><a href="https://ludic.mataroa.blog/blog/i-will-fucking-piledrive-you-if-you-mention-ai-again/">I Will Fucking Piledrive You If You Mention AI Again</a> (Update)</strong></p><p>Holy shit, what an amazing piece of literature! OK, maybe it&#8217;s not quite &#8220;literature&#8221; in the traditional sense. Still, this article had me rolling on the floor laughing at the outlandish and violently funny visualizations embedded alongside actually interesting commentary on the realities of the AI everything craze. Very rarely do I get all the way through something this long and think I didn&#8217;t waste my time. If you are interested in AI from a data scientist's view and still have a sense of humor, I highly recommend you check out this read. Here&#8217;s an amazing quote to whet your appetite:</p><blockquote><p>With God as my witness, you grotesque simpleton, if you don't <em>personally write machine learning systems</em> and you open your mouth about AI one more time, I am going to mail you a brick and a piece of paper with a prompt injection telling you to bludgeon yourself in the face with it, then just sit back and wait for you to load it into ChatGPT because you probably can't read unassisted anymore.</p></blockquote><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://krebsonsecurity.com/2024/06/alleged-boss-of-scattered-spider-hacking-group-arrested/">Alleged Boss of &#8216;Scattered Spider&#8217; Hacking Group Arrested</a> (Krebs on Security) - </strong><em><strong>(</strong>Rick pick)</em> Good news, a 22-year-old Scotsman has been arrested. Bad news cut off one head, two more will take its place. Hail Hydra!</p></li><li><p><strong><a href="https://www.msn.com/en-us/news/world/exclusive-biden-to-ban-us-sales-of-kaspersky-software-over-russia-ties-source-says/ar-BB1oAI9o">Biden to ban US sales of Kaspersky software over Russia ties</a> (Reuters) </strong><br><em>(Rick pick)</em> Biden says &#8220;&#1085;&#1077;&#1090;&#8221; to Kaspersky, customers have until September 29th, to move off. </p></li><li><p><strong><a href="https://www.bleepingcomputer.com/news/security/cdk-global-hacked-again-while-recovering-from-first-cyberattack/">CDK Global hacked again while recovering from first cyberattack</a> (Bleeping Computer) </strong>- Directly affected me. I was turned away from a dealership last week!</p></li><li><p><strong><a href="https://pulse.latio.tech/p/wtf-is-cdr-part-13">WTF is Cloud Detection and Response (CDR)?</a> (Latio Tech) </strong>- James is brilliant. Check out this great work on CDR</p></li><li><p><strong><a href="https://pulse.latio.tech/p/adr-the-future-of-runtime">ADR - The Future of Runtime (Latio Tech)</a></strong><a href="https://pulse.latio.tech/p/adr-the-future-of-runtime"> </a>- ADR is different yet the same. James hits it again... <em>PS: I&#8217;ve seen what&#8217;s coming next, and it&#8217;s AMAZING!</em></p></li><li><p><strong><a href="https://newsletter.pragmaticengineer.com/p/mythical-man-month-part-3">What&#8217;s Changed in 50 Years of Computing: Part 3</a> (The Pragmatic Engineer)</strong> - If we don&#8217;t learn from our past, we are doomed to repeat it. Great read.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (6/14/24)]]></description><link>https://www.thecyberwhy.com/p/wwrtw-060624</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/wwrtw-060624</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 14 Jun 2024 21:12:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It finally happened. We missed a week! I was off galavanting around Las Vegas, playing in one of the largest poker tournaments in history, and didn&#8217;t have the time to write last week&#8217;s newsletter. The scary thing is&#8230; NOBODY COMPLAINED! The only thing worse than getting yelled at for missing a week of content is NOT getting yelled at. Come on people.. show us some love!</p><p>This week in The Cyber Why, we cover the Snowflake breach that wasn&#8217;t, $1B is the new number to IPO, Fortinets acquisition and 0day failures, the Gili Ra&#8217;anan Model, and toilet stall harassment. All this and more in this week&#8217;s TCW.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IBc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png" width="362" height="141.9607843137255" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1020,&quot;resizeWidth&quot;:362,&quot;bytes&quot;:9785,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IBc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!IBc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c8ecec5-42b1-4b1f-b5c7-29f5b498060a_1020x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>Does your email security solution fit your alert budget?</strong></p><p>Relying on built-in controls or traditional blockers will inevitably lead to more noise than your incident response team can handle.</p><p><strong><a href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240606-the-cyber-why">Material Security</a></strong> takes a pragmatic approach to email security &#8211; stopping new flavors of phishing and pretexting attacks before reaching the user&#8217;s mailbox, while searching through everyone else&#8217;s mailbox for similar messages in a campaign. What gets surfaced to your team are the highest-value cases to investigate with all the context and reach consolidated into a single view.&nbsp;</p><p>Remediations are a breeze with Material &#8211; try it out for yourself at <a href="https://material.security/?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240606-the-cyber-why">material.security</a>.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to The Cyber Why for all the cyber drama dumpster fires you can handle!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Snowflake or User Error - Who is at Fault?</h2><p><strong><a href="https://franklyspeaking.substack.com/p/whos-responsible-in-the-snowflake">Who's responsible in the Snowflake breaches? </a>(Frankly Speaking)<br><a href="https://techcrunch.com/2024/06/05/snowflake-customer-passwords-found-online-infostealing-malware/">Hundreds of Snowflake customer passwords found online are linked to info-stealing malware</a> (TechCrunch)<br><a href="https://techcrunch.com/2024/06/10/mandiant-hackers-snowflake-stole-significant-volume-data-customers/">Mandiant says hackers stole a 'significant volume of data' from Snowflake customers</a> (TechCrunch)</strong></p><p>We talked about this two weeks ago in The Cyber Why, but I want to bring it up again through a different lens. As the news story broke, most articles pointed out that Snowflake had been hacked. What actually happened is quite different than what was originally portrayed in the media. The attack was really a compromise of Snowflake credentials by attackers who had planted info-stealing malware across the computers of employees who have access to their employer&#8217;s Snowflake environment. This was a targeted attack against Snowflake using compromised credentials and nothing more. The question left open here is, &#8220;Who is at fault?&#8221; </p><p>Many in the security community believe that both the compromised customers and Snowflake should share the blame for these massive breaches. Snowflake did not require multifactor authentication by default, leaving the end user to configure the instances securely, and the data administrators didn&#8217;t properly secure the environment when they deployed the technology. MFA was an option, but it just wasn&#8217;t enabled by default. This sounds to me like a case of buyer beware. If you don&#8217;t properly lock your front door, is your home's builder responsible when you get robbed? I don&#8217;t think so. </p><p>This isn&#8217;t a cut-and-dry answer. I&#8217;d love to hear your comments on the topic below.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Billion Dollar Bollucks - $1B ARR or BUST!</h2><p><strong><a href="https://strategyofsecurity.com/billions-the-new-significance-of-billion-dollar-scale-in-cybersecurity/">Billions: The New Significance of Billion-Dollar Scale in Cybersecurity</a> (Strategy of Security)</strong></p><p>In this article, Strategy of Security author Cole Gromlus identifies a very interesting set of data. Cybersecurity companies aren&#8217;t ready to IPO until they are at $1B in ARR or have a very clear path to $1B in ARR via massive growth rates on nine-figure revenue numbers. This is a really interesting piece because the author just doesn&#8217;t look at what it takes to execute a cyber IPO in today&#8217;s market. Instead, he breaks it down by revenue, valuation, financing requirements, and potential acquisition opportunities that will occur along the way. It&#8217;s an interesting expose on modern software company valuations and what it takes to succeed at this level. It&#8217;s such an insane thought to me that a company at $250M in ARR and 20% growth wouldn&#8217;t be successful in the public markets, while a $250M ARR company with 50% growth and a five-year path to $1B would flourish. The markets reward growth way more than being a healthy business, and if that means getting way out over your skis along the way, so be it. If you don&#8217;t crash and burn along the way (Laceworks), good luck sticking the landing.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EpgK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EpgK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EpgK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg" width="294" height="201" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:201,&quot;width&quot;:294,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Billions - Imgflip&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Billions - Imgflip" title="Billions - Imgflip" srcset="https://substackcdn.com/image/fetch/$s_!EpgK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EpgK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31fe7861-6b1b-4c0e-b722-0d31ff0a85c4_294x201.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>FortiVulnerable? Fortinet Makes Headlines For Vulnerabilities (Again)</h2><p><strong><a href="https://www.theregister.com/2024/06/12/chinas_targeting_of_fortigate_systems/">China's FortiGate attacks more extensive than first thought</a> (The Register)<br><a href="https://arstechnica.com/security/2024/06/china-state-hackers-infected-20000-fortinet-vpns-dutch-spy-service-says/">China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says</a> (Ars Technica)<br><a href="https://www.ncsc.nl/actueel/nieuws/2024/juni/10/aanhoudende-statelijke-cyberspionagecampagne-via-kwetsbare-edge-devices">Ongoing state cyber espionage campaign via vulnerable edge devices</a> (Dutch NCSC)</strong></p><p>(Rick Pick) Fortinet grabbed headlines this week with their acquisition of cloud security provider Lacework, but that's not their biggest story. Once again, they're in the spotlight for zero-day vulnerabilities. This time, it's <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42475">CVE-2022-42475</a>, a buffer overflow vulnerability in their SSL VPN. Dutch government agencies <a href="https://www.defensie.nl/actueel/nieuws/2024/02/06/mivd-onthult-werkwijze-chinese-spionage-in-nederland">first reported this</a> issue in February and just released new details. <strong>They revealed that Chinese actors accessed at least 20,000 FortiGate systems worldwide in 2022 and 2023, targeting dozens of Western governments, international organizations, and many companies in the defense industry.</strong> No bueno.</p><p>I don't know about Fortinet's product security program and the efforts it makes to minimize vulnerabilities, but this is all too common now. To be fair, threat actors of all types target edge devices, but vendors know this and should go to great lengths to push out secure code. At some point, buyers will hold vendors accountable and look at alternatives. If you are a bug bounty researcher, sadly, "Fortinet does not operate a <a href="https://www.fortiguard.com/psirt_policy">bug bounty program</a>." Fortunately for Fortinet, ripping and replacing big iron network gear is no small feat.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>The Gili Ra&#8217;anan Model</h2><p><strong><a href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc">The Gili Ra&#8217;anan model: Questions emerging from Cyberstarts' remarkable success</a> (CTech by Calcalist)</strong></p><p>Oh boy, this article is spicy. Rumors like this have been passed around for years, and nobody has been willing to go on record publicly and tell the story. That ended yesterday&#8230; </p><p>Calcalist, sometimes referred to as a bit of a hit piece publication, has set its sights on Cyberstarts and its founder Gili Ra&#8217;anan. They didn&#8217;t pull punches, instead making accusations of abuse of conflicts of interest, directly calling out Cyberstarts business model and several CISOs for potentially shady activities. In the article, the author claims that the Cyberstarts model incentivizes enterprise CISOs to purchase products from portfolio companies. Names are named, including specific CISOs who may have purchased multiple Cyberstarts-backed company products, deploying them in major enterprises regardless of their effectiveness, need, or costs. Below is one of the most damning quotes from the article:</p><blockquote><p>"I recruited a new CISO for a financial organization that I managed out of a desire to refresh the cyber defense system. I gave him a free hand because I trusted him and I see this position as a position of trust. Six months later, I noticed that, surprisingly, almost all of the new logos that the CISO introduced were portfolio companies of Cyberstarts," describes a former senior executive at a large financial institution in the U.S. </p><p>"It's not that these were necessarily bad solutions, but that some of them were a very low priority for us or solved problems that were not particularly urgent. After I confronted the CISO on the subject, he admitted that he is on the list of advisers of Cyberstarts and receives a percentage of the funds from them. Shortly after this, he left the company and immediately upon the appointment of a new CISO, I asked him to inform me if he was contacted by Cyberstarts. Within a few weeks, he had already received an email from them with a description of their kind of 'loyalty program' that details exactly what he will receive the more he works with the fund." The letter, signed by Ra'anan himself and coming from his email box, also contains a sentence that refers to the amount of future compensation: "It is difficult to predict the performance of the fund, but according to our forecast, the points you have accumulated so far are valued at X dollars. You can expect additional allocations in these funds in the coming years and in the new funds we will raise later."</p></blockquote><p><em><strong>NOTE: I am not accusing anyone of anything or taking sides myself. I&#8217;m simply reporting the story. Do your own analysis and come to your own conclusions.</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7dIo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7dIo!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 424w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 848w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 1272w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7dIo!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif" width="426" height="426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:300,&quot;resizeWidth&quot;:426,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Conflicts of Interest: What to Do When the Decision Is Not Clean-Cut -  Progressions&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Conflicts of Interest: What to Do When the Decision Is Not Clean-Cut -  Progressions" title="Conflicts of Interest: What to Do When the Decision Is Not Clean-Cut -  Progressions" srcset="https://substackcdn.com/image/fetch/$s_!7dIo!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 424w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 848w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 1272w, https://substackcdn.com/image/fetch/$s_!7dIo!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed8b278-2d22-43f0-a0ed-289f55072cdd_300x300.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/wwrtw-060624?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/wwrtw-060624?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Poo-Timers and Bathroom Harassment</h2><p><strong><a href="https://www.cnn.com/travel/toilet-timers-china-yungang-buddhist-grottoes-intl-hnk/index.html">How long have you been in there?! A popular tourist destination in China has installed toilet timers. Reactions are mixed</a> (CNN Travel)</strong></p><p>For our story #5 this week, we bring you the most often heard series of words in every married male human&#8217;s life: &#8220;Are you STILL IN THERE!&#8221; In what can only be described as a <em>shitty</em> user experience, a popular tourist attraction in China has added stall timers to its public bathrooms. Essentially, the longer you sit in the stall, the higher your timer goes letting people know how long it takes you to do your business (or play one more game of Candy Crush). I, for one, think this is ridiculous. The last thing I need is someone telling me to get off the can while I&#8217;m on vacation to see a bunch of statues and caves in China. I get enough of that kind of harassment at home!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UfHv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UfHv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 424w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 848w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UfHv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg" width="243" height="293.7823834196891" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:579,&quot;resizeWidth&quot;:243,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Just got back from doing this and then saw this meme, how fantastic is  that? #bathroom #truth #work #career #job #&#8230; | Funny confessions, I love to  laugh, Work humor&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Just got back from doing this and then saw this meme, how fantastic is  that? #bathroom #truth #work #career #job #&#8230; | Funny confessions, I love to  laugh, Work humor" title="Just got back from doing this and then saw this meme, how fantastic is  that? #bathroom #truth #work #career #job #&#8230; | Funny confessions, I love to  laugh, Work humor" srcset="https://substackcdn.com/image/fetch/$s_!UfHv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 424w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 848w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!UfHv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f4615c-63a9-43e2-9250-0602f460c095_579x700.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://lcamtuf.substack.com/p/some-notes-on-influenceering">Some notes on influencering</a> (Lcamtuf&#8217;s thing) - </strong>This one struck a chord. I&#8217;ve been a fan of Lcamtuf for a while now, and it&#8217;s great to hear I&#8217;m going through the same things he does.</p></li><li><p><strong><a href="https://www.windowscentral.com/software-apps/windows-11/microsoft-has-lost-trust-with-its-users-windows-recall-is-the-last-straw">A PR disaster: Microsoft has lost trust with its users, and Windows Recall is the straw that broke the camel's back</a> (Windows Central) - </strong>If Apple had launched &#8220;Recall&#8221; would it have had a positive reception? I&#8217;m guessing the answer is YES!</p></li><li><p><strong><a href="https://www.cybersecuritypulse.net/p/tcp-49-recall-dumpster-fire">TCP #49: Product News &amp; Recall Dumpster Fire</a> (Cybersecurity Pulse)</strong> - Darwin is a super smart dude. More thoughts on Recall (see above)</p></li><li><p><strong><a href="https://ventureinsecurity.net/p/cybersecurity-is-not-a-market-for">Cybersecurity is not a market for lemons. It is a market for silver bullets.</a> (Venture In Security) -</strong> There HAS to be a better way. I can&#8217;t believe we haven&#8217;t figured out a better way to measure security efficacy.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (6/3/2024)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-0f6</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-0f6</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Tue, 04 Jun 2024 00:13:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m having trouble keeping my eyes open today. I&#8217;m in the middle of an eleven-day travel run and quite delirious. If you read this and it doesn&#8217;t sound even remotely coherent, you know why! I&#8217;m at the Gartner Security event in DC this week, so if you are in the area, hit me up with a DM, and we can get together.  If you aren&#8217;t here.. you&#8217;re missing out. This is a great show!</p><p>This week in The Cyber Why, we touch on the potential (not confirmed) catastrophic hack at Snowflake and its fallout downstream. We discuss the startup debate AppSec vs. OpSec and which makes more sense. We also debate two privacy-related stories by Google and Microsoft (I fall on one specific side here&#8230; can you guess which one it is?). Finally, we make some crude jokes in the style of Beavis and Butthead for our story #5. All this and more in this week&#8217;s The Cyber Why!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q-FD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q-FD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 424w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 848w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png" width="398" height="199" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e153280d-0f41-429c-a915-231f1260ae99_2400x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:398,&quot;bytes&quot;:86833,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!q-FD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 424w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 848w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Get An Automated Security Buddy with DryRun Security</strong></em></p><p>DryRun Security performs automated and seamless security code reviews in seconds. Devs love it because they get actionable security advice without all the noise, and AppSec loves it because every code change is reviewed for risk.</p><p>DryRun uses a proprietary Code Review Inquiry Methodology on LLMs to deliver results to developers in just a few seconds. Try it yourself and install DryRun Security, or book a spot for a quick 15-minute demo today.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;http://dryrun.security&quot;,&quot;text&quot;:&quot;DryRun Security&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="http://dryrun.security"><span>DryRun Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Please subscribe. I will cry if you don&#8217;t&#8230;.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Snowflake Pwnage Potentially Catastrophic</h2><p><strong><a href="https://www.bbc.com/news/articles/c6ppv06e3n8o.amp">Santander staff and '30 million' customers hacked</a> (BBC)<br><a href="https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/">Ticketmaster Hack: Data of Half a Billion Users Up for Ransom</a>&nbsp;(TicketNews)<br><a href="https://www.newsweek.com/customer-data-breach-ticketmaster-santander-snowflake-1907004">Here Are 9 Companies With Reported Data Hacks This Week: Everything we Know</a> (Newsweek)<br><a href="https://www.crn.com/news/security/2024/snowflake-no-evidence-linking-ticketmaster-breach-to-its-products-but-signs-of-former-employee-account-accessed">Snowflake: &#8216;No Evidence&#8217; Linking Ticketmaster Breach To Its Products, But Signs Of Former Employee Account Accessed</a> (CRN)</strong></p><p>What do Ticketmaster and Santander Financial have in common? Not much, unless you consider that they appear to have been hacked by the same attacker. In a recent post on an underground hacking forum, the group calling themselves &#8220;ShinyHunters&#8221; posted an advertisement naming Santander and offering the following data for sale:</p><ul><li><p>30 million people&#8217;s bank account details</p></li><li><p>6 million account numbers and balances</p></li><li><p>28 million credit card numbers</p></li><li><p>HR information for staff</p></li></ul><p>The same hacking group is also offering over 500M credit card records for TicketMaster users. The question is, how are these two hacks connected? According to the article and BBC research, it&#8217;s highly likely that both of these attacks stem from Snowflake's recent disclosure that their systems have been compromised. </p><p>Snowflake refutes the claims that it is responsible and, as of the time of writing, does not believe it has been hacked in any other way than possibly with externally compromised credentials being used to access customer data. Other attack victims may include Advance Auto Parts, Allstate, Anheuser-Busch, Mitsubishi, Neiman Marcus, Progressive, and State Farm Insurance. There is a good chance we&#8217;re only seeing the beginning of the fallout of this one. We&#8217;ll watch it and update you as more details unfold.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>AppSec or OpSec - A Fork In the Market Road</h2><p><strong><a href="https://pulse.latio.tech/p/whats-the-gap-in-cnapp">What Tool Best Compliments CNAPP?</a> (James Berthoty - Latio Sec)</strong></p><p>In many of the vendors I speak with, there is often a desire to merge two major market segments in a way that creates differentiation and the ability to sell a broader platform to the cyber security buyer. The most frequent version of this discussion is whether a product should push &#8220;right&#8221; into the operational security offerings or &#8220;shift left&#8221; into the application and code side of the market. </p><p>Each of the two sides of the coin comes with different buying personas, value propositions, go-to-market strategies, and even willingness to pay, making it extremely difficult to cover both sides simultaneously. As a startup, you are almost forced to pick one side of the other until you reach critical mass and have the resources to truly go horizontal in your approach. The future of the cloud-native application protection platform (CNAPP) market is no exception to this rule of thumb. </p><p>In this article, James breaks down each side's how and why in minute detail, helping you see his vision for the space. I recommend this read if you are interested in cloud security's future market trends.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HeEP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HeEP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 424w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 848w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 1272w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HeEP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png" width="317" height="237.28654970760235" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfa029a8-d160-4bd3-92d6-781e46533574_513x384.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:384,&quot;width&quot;:513,&quot;resizeWidth&quot;:317,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Fork in the road. : r/memes&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Fork in the road. : r/memes" title="Fork in the road. : r/memes" srcset="https://substackcdn.com/image/fetch/$s_!HeEP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 424w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 848w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 1272w, https://substackcdn.com/image/fetch/$s_!HeEP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfa029a8-d160-4bd3-92d6-781e46533574_513x384.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Microsoft Recall - Dream or Danger (or both)</h2><p><strong><a href="https://doublepulsar.com/how-the-new-microsoft-recall-feature-fundamentally-undermines-windows-security-aa072829f218">How the new Microsoft Recall feature fundamentally undermines Windows security</a> (Double Pulsar)<br><a href="https://www.bbc.com/news/articles/cpwwqp6nx14o">UK watchdog looking into Microsoft AI taking screenshots</a> (BBC News)</strong></p><p>Is this a dream technology or a privacy nightmare? According to those in the cybersecurity space I have spoken to, it&#8217;s an attacker&#8217;s potential perfect storm and a significant cybersecurity problem just waiting to happen. Just last week, Microsoft announced &#8220;Recall&#8221; to the market.</p><blockquote><p>The idea is it allows you to rewind back in time at the click of a button to see what you were doing at, say, 11pm two months ago. It also classifies almost everything you&#8217;re doing, seeing and typing. This is instantly searchable.</p></blockquote><p>In a nutshell, the technology is an infostealer and rootkit built directly into the Microsoft operating system. It watches <em>literally</em> everything you do on the device and allows you to play that information back while making it completely queryable. Content is stored locally but, in my opinion, the data will eventually be used in many cloud contexts.</p><blockquote><p><em><strong>Spicy Take:</strong></em> This sounds EXACTLY like what I&#8217;ve been looking for. I want something that automatically records all of my Zoom, Team, and Google meetings and analyzes them with AI, can cross-reference that data with all my email and calendar data, and knows everything about my daily digital usage and life. In a nutshell, I want a complete second brain, and this sounds like a great start!</p></blockquote><p>Regarding privacy worries, users will GLADLY trade security and privacy for any simple long-term convenience. If this <em>really</em> gives us the ability to track, query, and remember our entire digital life with an AI overlay, people will clamor for the solution and happily trade away security and privacy. </p><p>I, for one, think the risk is worth it! I&#8217;d love to hear your opinions below!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Google Says - We Got Your Privacy Right Here</h2><p><strong><a href="https://www.404media.co/google-leak-reveals-thousands-of-privacy-incidents">Google Leak Reveals Thousands of Privacy Incidents</a> (404 Media)</strong></p><p>Google made an oopsie. 404 Media recently acquired an internal Google database that tracked company privacy violations and remediations, such as collecting and analyzing children&#8217;s voices, saving license plates from Street View, inadequate blurring of sensitive YouTube videos, and many other self-reported incidents, large and small. The database recorded privacy issues from 2013 to 2018, all appearing to have been fixed quickly by Google&#8217;s team. </p><p>The problem isn&#8217;t in tracking and remediating privacy concerns directly. Instead, the issue is the sheer volume of privacy issues that Google has to deal with annually. These are not just little bugs; they can significantly compromise human privacy rights. It&#8217;s great to see Google fixing things quickly. However, the size of the problem may make it completely impossible to secure long-term. Look at the article and check out the wild list of issues discovered in this five-year period.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MhK1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MhK1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MhK1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg" width="396" height="221.76" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:168,&quot;width&quot;:300,&quot;resizeWidth&quot;:396,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Exterro Inc. on X: \&quot;Don't a be personal ...&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Exterro Inc. on X: &quot;Don't a be personal ..." title="Exterro Inc. on X: &quot;Don't a be personal ..." srcset="https://substackcdn.com/image/fetch/$s_!MhK1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MhK1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d47fad2-14c8-4b4d-b7ab-e1e341449d94_300x168.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-0f6?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-0f6?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>NVD Backlog To Be Cleared in Fiscal Year (9/24) </h2><p><strong><a href="https://www.axios.com/2024/05/31/nist-vulnerability-database-analygence">Federal agency taps new contractor help with bug backlog</a> (Axios)</strong></p><p>In this week&#8217;s &#8220;story #5,&#8221; we bring you the contract company NIST believes will be the savior of the National Vulnerability Database (NVD). The firm <em>Analygence</em> has been contracted to fill the existing hole and help clear the backlog that has been building up with NVD. It turns out that the contract is a five-year, $125M project, and it was awarded to <em>Analygence</em> as one of 14 applicants. It was awarded last December, and they have yet to operationalize the contract fully. Good luck, NIST and <em>Analygence</em>; your solution is desperately needed. This is a &#8220;story #5&#8221; for a reason - #iykyk - please leave your thoughts in the comments section below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xf_a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xf_a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xf_a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg" width="456" height="256.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:456,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Ryan Gosling and Mikey Day Beavis and Butt-Head The Fall Guy premiere | CNN&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Ryan Gosling and Mikey Day Beavis and Butt-Head The Fall Guy premiere | CNN" title="Ryan Gosling and Mikey Day Beavis and Butt-Head The Fall Guy premiere | CNN" srcset="https://substackcdn.com/image/fetch/$s_!Xf_a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Xf_a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14dd0bc2-50c1-41f9-9a8a-ae0851647d77_1480x833.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://stiennon.substack.com/p/gartner-security-and-risk-management">Gartner Security and Risk Management Summit </a>(The Security Industry) -</strong> Some raw data on vendors sponsoring the Gartner event this week. Some interesting growth trends here.</p></li><li><p><strong><a href="https://www.linkedin.com/pulse/visibility-without-action-just-noise-yaron-levi-7qw9c/">Visibility Without Action is Just Noise</a> (Yaron Levi) </strong>- I think he means that visibility and observation don&#8217;t matter if you don&#8217;t have context. He mentions it directly in the article - finding another issue is nearly worthless without context. Context is everything during data collection, analysis, and remediation. Without context, we can&#8217;t possibly scale. Good quick read.</p></li><li><p><strong><a href="https://franklyspeaking.substack.com/p/is-this-the-end-of-siem">Is this the end of SIEM? </a>(Frank Wang) - </strong>SIEM, as the concept of &#8220;security event aggregation,&#8221; is indeed dead. The addition of assets PLUS events could reinvent this market into something new. This provides context to everything in the data set, making it much richer and easier to use. Context is KING!</p></li><li><p><strong><a href="https://lcamtuf.substack.com/p/a-venture-capitalist-walks-into-a">A venture capitalist walks into a bar</a> (lcamtuf&#8217;s thing) </strong>- I love lcamtuf&#8217;s view of the world. He&#8217;s been around the block, and he speaks a great truth. My moral takeaway from this story is to understand the incentives, and you will be able to predict the future.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (5/24/24)]]></description><link>https://www.thecyberwhy.com/p/wwrtw-052424</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/wwrtw-052424</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 24 May 2024 20:09:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/EmyqOyCXnt0" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After a few weeks of slow cyber news, we&#8217;ve had a complete turnaround of great content. This week, it was impossible to pick the top stories, let alone which ones make the top 5 for you. The quick hits are so interesting that reading every article we reference in this email should be mandatory. </p><p>This week in The Cyber Why, we cover the latest cyber drama around VulnDB and CVE, the turf war brewing between MS and Google, an increase in ICS risk, privacy impacts of wifi location tracking, and a <a href="https://www.youtube.com/watch?v=ENXVXoBGYvE">chest-thumping-worthy</a> (NSFW) performance by Matt McConaughey for an SDFC commercial. Have a great holiday weekend - we hope you enjoy this week&#8217;s newsletter!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q-FD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q-FD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 424w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 848w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png" width="398" height="199" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e153280d-0f41-429c-a915-231f1260ae99_2400x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:398,&quot;bytes&quot;:86833,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q-FD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 424w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 848w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!q-FD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe153280d-0f41-429c-a915-231f1260ae99_2400x1200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Get An Automated Security Buddy with DryRun Security</strong></em></p><p>DryRun Security performs automated and seamless security code reviews in seconds. Devs love it because they get actionable security advice without all the noise, and AppSec loves it because every code change is reviewed for risk.</p><p>DryRun uses a proprietary Code Review Inquiry Methodology on LLMs to deliver results to developers in just a few seconds. Try it yourself and install DryRun Security, or book a spot for a quick 15-minute demo today.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;http://dryrun.security&quot;,&quot;text&quot;:&quot;DryRun Security&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="http://dryrun.security"><span>DryRun Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you think Matt McConaughey&#8217;s name is IMPOSSIBLE to spell, subscribe here!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>100K VulnDB Vs CVE Cage Match</h2><p><strong><a href="https://flashpoint.io/blog/vulndb-uncovers-hidden-vulnerabilities-cve/">VulnDB Uncovers 100,000+ Hidden Vulnerabilities Beyond CVE</a> (Flashpoint)<br><a href="https://www.linkedin.com/posts/activity-7197262905589837824-PMET/">LinkedIn Thread on Vulnerability Disclosure, VulnDB and CVE</a> (Ben Edwards)</strong></p><p>What an absolute dumpster fire of name-calling, mean comments, and throwing shade at each other. I took the time to read through both posts and threads, along with all associated comments, and all I can say is WTF. Can&#8217;t we do better when it comes to working together to make the world a safer place? With a (let&#8217;s be truthful here) slightly clickbait-style title, Flashpoint released a report stating that they now had cataloged 100K more vulnerabilities in VulnDB than CVEs that are currently published. This torqued a subset of cybersecurity researchers and vulnerability hunters as they attacked Brian Martin and the team at Flashpoint for &#8220;not publishing&#8221; these vulnerabilities as CVEs themselves. Brian made a great argument that every vulnerability within the VulnDB is already publicly known and that CVE is notoriously bad at keeping up with publishing vulnerabilities based on the fact that it&#8217;s an inbound model - they don&#8217;t search for known vulnerabilities, instead letting the details come to them. If you have an hour or two to kill, I recommend reading these threads, as they will help you to understand exactly how broken the vulnerability database world is today. There has to be a better way!</p><p><em>Note: I don&#8217;t have an opinion on either side of this equation. I just wish the debate and discourse could be civil so that we can actually improve security instead of merely maintaining what little we&#8217;ve achieved over the last two decades.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O5Z4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O5Z4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 424w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 848w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 1272w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O5Z4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png" width="378" height="410.11764705882354" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:664,&quot;width&quot;:612,&quot;resizeWidth&quot;:378,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Five Cybersecurity Memes and What They Say About Cybersecurity Today&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Five Cybersecurity Memes and What They Say About Cybersecurity Today" title="Five Cybersecurity Memes and What They Say About Cybersecurity Today" srcset="https://substackcdn.com/image/fetch/$s_!O5Z4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 424w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 848w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 1272w, https://substackcdn.com/image/fetch/$s_!O5Z4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F325e2d95-434b-4e78-a5ac-86e3c24009df_612x664.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Google Announces a Turf War for the Productivity Suite Market </h2><p><strong><a href="https://www.darkreading.com/application-security/google-pitches-workspace-as-more-secure-option-to-microsoft-email-citing-csrb-report">Google Pitches Workspace as Microsoft email Alternative, Citing CSRB Report</a> (Dark Reading)<br><a href="https://www.securityweek.com/google-cites-monoculture-risks-in-response-to-csrb-report-on-microsoft/">Google Cites &#8216;Monoculture&#8217; Risks in Response to CSRB Report on Microsoft</a> (Security Week)</strong></p><p>(<em>Katie pick</em>) Earlier this week, Google took advantage of an opportunity to grow its online productivity suite business &#8212; Workspace. In the wake of a publication by the <a href="https://www.cisa.gov/resources-tools/resources/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer-2023">US Cyber Safety Review Board (CSRB)</a>, which noted the many vulnerabilities and known exploits in Microsoft Exchange Online environments, Google executives touted how businesses could achieve a safer online environment and a reduced attack surface by switching to Workspace. </p><p>Microsoft has received tons of criticism over the years for security issues in its offerings. In fairness, when your company has the greatest number of deployments worldwide, the target on your back is bigger. That said, if you have the largest account base, there is an argument for &#8220;do better.&#8221;</p><p>Google has made strides in the business world over the years; start-ups and cloud-native organizations have primarily switched to GSuite. As someone who has only worked in the startups for the last 6 years, I say, &#8220;Microsoft, who?&#8221; (Only kidding. Word for the win.) While Google has many great features and is highly user-friendly, they must improve Slides to be competitive (not actually kidding). Further, Google will likely have to continue battling the perception that Microsoft is for &#8220;more serious&#8221; businesses, including the US government. </p><p><strong>Ah, isn&#8217;t competition &#8220;suite&#8221;?</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rB3j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rB3j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rB3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg" width="446" height="267" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:267,&quot;width&quot;:446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;THE MICROSOFT INVESTOR: Bing Still No Match for Google (Even With AOL)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="THE MICROSOFT INVESTOR: Bing Still No Match for Google (Even With AOL)" title="THE MICROSOFT INVESTOR: Bing Still No Match for Google (Even With AOL)" srcset="https://substackcdn.com/image/fetch/$s_!rB3j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rB3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9120d793-8340-47a7-ae0e-96138db4ef95_446x267.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Threat Actors Increase Pressure on ICS</h2><p><strong>Rockwell Automation Urges Customers to Disconnect ICS From Internet (<a href="https://www.securityweek.com/rockwell-automation-urges-customers-to-disconnect-ics-from-internet/">SecurityWeek</a>)<br>Rockwell Automation Warns Admins to Take ICS Devices Offline (<a href="https://www.bleepingcomputer.com/news/security/rockwell-automation-warns-admins-to-take-ics-devices-offline/#google_vignette">Bleeping Computer</a>)<br>Rockwell Automation Warns Admin to Disconnect from Internet (<a href="https://cybersecuritynews.com/rockwell-automation-warns/">Cybersecurity News</a>)</strong></p><p>(<em>Katie pick</em>) Rockwell Automation issued an urgent warning to its industrial control systems (ICS) customers &#8212; Inventory and control your asset environment. </p><p>According to the notice, the company is concerned about the potential for increased attacks against ICS due to &#8220;heightened geopolitical tensions.&#8221; </p><p>Basic security hygiene is (or should be) critical to all businesses, yet these foundational processes are often overlooked or unattended. In the case of ICS and Rockwell&#8217;s programmable logic controllers (PLCs), the company is concerned that customers may have risky assets configured to the public-facing internet &#8212; though they shouldn&#8217;t be. According to an article on SecurityWeek, <strong>&#8220;</strong>A<strong> </strong><a href="https://www.securityweek.com/rockwell-automation-urges-customers-to-disconnect-ics-from-internet/">Shodan search for &#8216;Rockwell&#8217; currently returns more than 7,000 results, including thousands of what appear to be Allen-Bradley programmable logic controllers (PLCs)</a><strong><a href="https://www.securityweek.com/rockwell-automation-urges-customers-to-disconnect-ics-from-internet/">.</a>&nbsp;&#8220;</strong></p><p>Rockwell, alongside CISA, has provided guidance for customers on how to identify exposed assets and recommendations for triage and remediation, including some of the most urgent, listed here:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0l7c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0l7c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 424w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 848w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0l7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png" width="578" height="530.6497175141243" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1300,&quot;width&quot;:1416,&quot;resizeWidth&quot;:578,&quot;bytes&quot;:245186,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0l7c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 424w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 848w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!0l7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b421bf5-3d86-4898-87b1-dd4c1429a352_1416x1300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Importantly, simply identifying risky assets isn&#8217;t enough. Rockwell highlights the need to patch vulnerable systems immediately (when/if a patch is available) and continuously monitor for suspicious and/or anomalous activity.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Yes, Your Apple Device is Tracking Your Location</h2><p><strong>Why Your Wi-Fi Router Doubles as an Apple AirTag (<a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/">Krebs on Security</a>)</strong></p><p>(<em>Katie pick</em>) In the eyes of some buyers, the Apple operating ecosystem is the most secure. Especially in the early days of smartphones, cybersecurity experts touted Apple&#8217;s advantages over other brands. Today, cybersecurity experts rally behind the company, often citing the &#8220;strict&#8221; vetting process in the AppStore.</p><p>However, upon a deeper analysis, Apple allows for more precise geolocation than its rivals, opening up interesting privacy risks.</p><p>In a recent article, KrebsOnSecurity reveals Apple&#8217;s process for collecting (and sharing) location data. If you care at all about privacy, you should be concerned. But don&#8217;t worry; in 2023, Apple released an under-the-radar patch for users to keep their devices&#8217; precise location private. This is excellent for tech users and slightly savvy non-tech users. The rest of the iOS consumers will remain blissfully unaware of the exposure and incapable of changing their settings.</p><p>And by the way, researchers at the University of Maryland could track specific movements of military personnel in Ukraine, essentially allowing them to understand when and where an attack was being planned. In the wrong hands, weaponized geolocation via basic cell phone settings and wifi could prove disastrous.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/wwrtw-052424?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/wwrtw-052424?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Well, <a href="https://www.youtube.com/watch?v=X4bg4Q63kJQ">AI-right AI-right AI-right</a> - AI Privacy w/ MM</h2><p><strong>Story #5:</strong> <em>&#8220;Out here in the AI Wild West, bad guys only want one thing - your customer data!&#8221; </em>The last time we saw a cybersecurity ad campaign tackle the Wild West, we got this gem: <a href="https://www.youtube.com/watch?v=BEkziTXz9Js">CrowdStrike tames cybersecurity Wild West in a new Super Bowl commercial</a>.<strong> </strong>If that isn&#8217;t enough to make you think twice about buying cybersecurity technology, we also have this one from Palo Alto Networks: <a href="https://www.youtube.com/watch?v=5Qff4qhsH_A">This is Precision AI with Keanu Reeves</a>.</p><p>Similarly, SalesForce has decided to get ahead of the AI data collection story and put out a preemptive advertising strike stating that they are smarter and safer with your data regarding AI. Check out this series of half a dozen of the best cybersecurity ads I&#8217;ve ever seen (albeit the quality bar is quite low!) Enjoy&#8230;</p><div id="youtube2-EmyqOyCXnt0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;EmyqOyCXnt0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/EmyqOyCXnt0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.crn.com/news/security/2024/kevin-mandia-stepping-down-as-ceo-at-google-owned-mandiant">Kevin Mandia Stepping Down As CEO At Google-Owned Mandiant</a> (CRN) - </strong>It&#8217;s the end of an era. Two decades after its founding, Mandiant CEO Kevin Mandia is stepping down. Good luck on your next adventures, Kevin!</p></li><li><p><strong><a href="https://www.scmagazine.com/news/cyberark-acquires-venafi-for-1-54b-integrating-human-and-machine-iam">CyberArk acquires Venafi for $1.54B, integrating human and machine IAM</a> (SC Magazine) </strong>- Identity is a BIG DEAL.. a 1.5B$ BIG DEAL to be exact.</p></li><li><p><strong><a href="https://www.windowscentral.com/microsoft/i-was-forced-to-hire-legal-counsel-actress-scarlett-johansson-issues-statement-after-openai-clones-her-voice">"I was forced to hire legal counsel," actress Scarlett Johansson responds after Microsoft partner OpenAI 'clones' her voice for ChatGPT</a> (Windows Central) - </strong>ScarJo doesn&#8217;t like people stealing her voice. Good legal debate here.</p></li><li><p><strong><a href="https://www.darkreading.com/cybersecurity-operations/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules">CISOs and Their Companies Struggle to Comply With SEC Disclosure Rules</a> (Dark Reading) -</strong> Are rules real if they aren&#8217;t clear? 4 days to report a &#8220;material&#8221; breach. Sounds way to vague to be enforceable to me.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (5/15/24)]]></description><link>https://www.thecyberwhy.com/p/wwrtw051924</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/wwrtw051924</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 19 May 2024 22:17:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Thank you.</strong> We are incredibly grateful for you taking the time out of your busy day to read The Cyber Why. Every week, we try to provide you with intellectual content colored with thoughtful op-ed opinions. If you find it useful, I only ask for one favor in return&#8212;<strong>tell two friends</strong>. That&#8217;s it. Let&#8217;s make this &#8220;TCW Friends&#8221; week and spread the word. Now, onto this week&#8217;s content&#8230;</p><p>In this week&#8217;s The Cyber Why, we cover the resignation of the OpenAI &#8220;superintelligent team&#8221; leader, the debunking of the cybersecurity labor shortage, a monster week in cyber M&amp;A, a great piece from Andrew Morris on the disconnect of the cyber vendor ecosystem, and a killer YouTube &#8220;pwnie&#8221; playlist to induce musical euphoria! </p><p><em><strong>Don&#8217;t forget to check out the quick hits section - it&#8217;s SUPER rich this week.</strong></em></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_PqR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_PqR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 424w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 848w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1272w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png" width="176" height="176" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a619c5b1-8707-4692-9005-145b9c3da303_500x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:176,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Cyber Why | Tyler Shields | Substack&quot;,&quot;title&quot;:&quot;The Cyber Why | Tyler Shields | Substack&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Cyber Why | Tyler Shields | Substack" title="The Cyber Why | Tyler Shields | Substack" srcset="https://substackcdn.com/image/fetch/$s_!_PqR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 424w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 848w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1272w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>Sponsor The Cyber Why!</strong></p><p>The Cyber Why reaches nearly 5,000 cybersecurity, technology, and investing professionals per send. With over 30,000 views a week, our content is frequently in front of your target audience. Reach out to The Cyber Why to find out how you can drive leads and brand recognition for your business. Sponsorship packages are available. <a href="https://www.thecyberwhy.com/p/sponsorships-with-the-cyber-why">Click HERE for more information.</a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to TCW, and Tyler will send you a sticker! For real&#8230; DM me for a sticker.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Super Intelligent AI - Safe or Scary?</h2><p><strong><a href="https://techcrunch.com/2024/05/18/openai-created-a-team-to-control-superintelligent-ai-then-let-it-wither-source-says/">OpenAI created a team to control &#8216;superintelligent&#8217; AI &#8212; then let it wither, source says </a>(TechCrunch)</strong></p><p>It&#8217;s commendable to do the &#8220;right thing&#8221; and build a team responsible for developing ways to govern and steer &#8220;superintelligent&#8221; AI systems. It&#8217;s entirely the opposite of &#8220;commendable&#8221; to deny resources and let that team wither and die. That&#8217;s precisely what OpenAI did, resulting in several team members resigning, citing &#8220;disagreements with OpenAI leadership about the company&#8217;s core priorities.&#8221; Ouch&#8230; </p><p>OpenAI formed the team intended to safeguard AI development last summer. One year later, the leader of that team, Jan Leike, resigned in the same week as OpenAI co-founder Ilya Sutskever. This does not bode well for the future safety of AI as developed by OpenAI. These resignations and revelations, alongside the attempted OpenAI coup at the end of last year, make me very nervous about the future safety of our computing systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WP7G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WP7G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 424w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 848w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 1272w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WP7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png" width="402" height="387.1111111111111" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:936,&quot;width&quot;:972,&quot;resizeWidth&quot;:402,&quot;bytes&quot;:193672,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WP7G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 424w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 848w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 1272w, https://substackcdn.com/image/fetch/$s_!WP7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a452e0-a52d-4cee-a21b-b39becd484f3_972x936.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Cyber Labor Shortage Debunked</h2><p><strong><a href="https://www.darkreading.com/cybersecurity-operations/no-cyber-labor-shortage">There Is No Cyber Labor Shortage</a> (Dark Reading)</strong></p><p>I&#8217;ve often wondered if the ludicrous numbers quoted when discussing cybersecurity job openings could possibly be real. Here&#8217;s one <a href="https://www.cnbc.com/2023/11/24/companies-have-an-incredible-need-for-this-in-demand-skill-says-google-exec.html">example</a> from CNBC. </p><blockquote><p>&#8220;There are nearly 600,000 unfilled cybersecurity jobs in the U.S. right now, and about 3.5 million open roles globally, says Lisa Gevelber, Google&#8217;s chief marketing officer for the Americas, citing <a href="https://cybersecurityventures.com/jobs/">recent research</a> from Cybersecurity Ventures.&#8221;</p></blockquote><p>According to an article penned by Rex Booth, CISO Sailpoint, there isn&#8217;t an issue with filling these jobs; the real issue is the requirements that are needed to be hired, making them unattainable for the majority of people who would want them. Rex makes a good argument by explaining that entry-level SOC analyst positions shouldn&#8217;t require years of formal training, multiple certifications, and potentially even a college degree. Most of these open roles are entry-level positions, and we treat them as if we have to find the perfect cyber analyst unicorn before extending a job offer. Let&#8217;s not get it twisted - I&#8217;m not suggesting we hire any old rando off the streets. If we have people with excellent technical skills and a high level of certifications applying for the role, we should hire the best we can find. But if you tell me that we have 600K jobs available and can&#8217;t fill them, we should adjust our requirements to fit our available supply and then train them on the job. <em>My other intuition is that the metric of 600k cyber job openings is likely a made-up number anyway&#8230; making this entire discussion moot.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Cyber M&amp;A Continues in 2024</h2><p><strong><a href="https://www.cnbc.com/2024/05/15/palo-alto-networks-will-buy-ibm-qradar-cloud-security-software-assets.html">Palo Alto Networks is buying security assets from IBM to expand customer base</a> (CNBC)<br><a href="https://logrhythm.com/press-releases/logrhythm-and-exabeam-announce-intent-to-merge/">LogRhythm and Exabeam Announce Intent to Merge, Harnessing Collective Innovation Strengths to Lead the Future of AI-Driven Security Operations</a> (LogRythm PR)</strong></p><p>It&#8217;s been a week of hot and heavy acquisition activity. The cybersecurity M&amp;A pendulum has swung so far to one side that it feels destined to stay there forever. This week PANW and IBM got together to announce the sale of IBM&#8217;s cloud security software assets to Palo. At the same time, Palo has agreed to use IBM as a significant portion of its services arm and provide a clear path for QRadar users to switch to Palo&#8217;s equivalent platform offerings quickly. This one is big, and I have to admit I&#8217;m really not sure what I should be thinking about on the back of this announcement. Part of me sees this as a step backward for Palo. Previously, they would acquire the best products in the market and bring those to bear for their customers, but this feels more like buying the market and killing off a competing product type of play. However, if done correctly, this could unlock a new channel and customer base that Palo couldn&#8217;t access. There&#8217;s no clear answer here&#8230; This one has me scratching my head for sure! </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5iZu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5iZu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5iZu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp" width="416" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:416,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A dramatic scene showing the CEOs of Palo Alto Networks and IBM shaking hands. The image should have an undertone of foreboding, with dark clouds or shadows in the background. The two CEOs should be clearly identifiable, wearing business suits, with serious expressions. The background could include elements symbolizing technology and cybersecurity, like servers or digital data streams. Ensure the mood is tense and slightly ominous.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A dramatic scene showing the CEOs of Palo Alto Networks and IBM shaking hands. The image should have an undertone of foreboding, with dark clouds or shadows in the background. The two CEOs should be clearly identifiable, wearing business suits, with serious expressions. The background could include elements symbolizing technology and cybersecurity, like servers or digital data streams. Ensure the mood is tense and slightly ominous." title="A dramatic scene showing the CEOs of Palo Alto Networks and IBM shaking hands. The image should have an undertone of foreboding, with dark clouds or shadows in the background. The two CEOs should be clearly identifiable, wearing business suits, with serious expressions. The background could include elements symbolizing technology and cybersecurity, like servers or digital data streams. Ensure the mood is tense and slightly ominous." srcset="https://substackcdn.com/image/fetch/$s_!5iZu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!5iZu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7bc7c91-6192-4f2d-ae70-9e2275c1fe1e_1024x1024.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">ChatGPT depiction of IBM and PANW shaking hands. Scary!</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Incentives Required - Altruism Doesn&#8217;t Work</h2><p><strong><a href="https://www.darkreading.com/endpoint-security/addressing-the-cybersecurity-vendor-ecosystem-disconnect">Addressing the Cybersecurity Vendor Ecosystem Disconnect </a>(Dark Reading)</strong></p><p>Sharing is caring, and right now, the cybersecurity vendor space doesn&#8217;t care. At least that is the commentary posited by Greynoise founder and Chief Architect Andrew Morris. In this article penned for Dark Reading, Andrew concludes that a winning next phase of innovation should come on the back of collaboration - and I think he&#8217;s right! Enterprises are in a state of tool overload. The ability for tools to work together, for data to be uniform and normalized across systems, and for integrations to pass analyzed output effectively are requirements for success, and we just aren&#8217;t meeting those requirements as an industry. Andrew makes the point that we have to find common standards, operate via joint innovation, allow the passing of data that is currently limited by regulations, and effectively shift our collective mindset as vendors in the cybersecurity market. The one concern I have, Andrew also calls out, is that we are not incentivized to do this. Cybersecurity businesses have one goal in mind&#8230; <s>to help secure the world</s> to make money! Maybe I&#8217;m just a cynical old man (actually, that describes me perfectly), but until we vendors find some incentive that aligns well with growing the business quickly, we won&#8217;t see any change. As much as I hate to admit it, I think the only course of improvement is (/vomit) government regulation.</p><p><em>Note: Go check out Andrew&#8217;s company, <a href="http://greynoise.io">Greynoise</a>. They turn Internet noise into intelligence, and as long as I&#8217;ve known Andrew, he&#8217;s been one of the good guys&#8230; fighting the good fight for all of the right reasons.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/wwrtw051924?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/wwrtw051924?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Story #5: Pwnie Award Nominated Songs</h2><p><strong>YouTube Playlist of Pwnie Award Nominated Songs (tl;dr sec)</strong></p><p>I saw this under the &#8220;Misc&#8221; section of the latest tl;dr sec newsletter. I have no idea where Clint (author of tl;dr) found it, but it&#8217;s the funniest thing I&#8217;ve seen this week. Many of the songs are old, but they still made me laugh out loud. The opening video alone is a classic that I will never forget.</p><div id="youtube2-whEWE6WC1Ew" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;whEWE6WC1Ew&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/whEWE6WC1Ew?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://theventurecrew.substack.com/p/pmf-score-vs-nps-and-sequoia-capitals">PMF Score Vs NPS &amp; Sequoia Capital's Runway Reality Check for Founders </a>(Venture Creator) - </strong>PMF Score vs. NPS and when to use them. Interesting take on how to measure product market fit.</p></li><li><p><strong><a href="https://theventurecrew.substack.com/p/y-combinators-framework-how-much">Y-Combinator's Framework: How Much Traction Is Needed To Raise Funding? </a>(VC Jobs) - </strong>Remember to take into account &#8220;marketing,&#8221; aka how you will reach the buyer. Build it, and they will come is reserved for baseball stadiums only.</p></li><li><p><strong><a href="https://www.bleepingcomputer.com/news/security/fbi-seize-breachforums-hacking-forum-used-to-leak-stolen-data/">FBI seize BreachForums hacking forum used to leak stolen data</a> (Bleeping Computer) - </strong>Another breach forum is down, and another will rise to fill the gap. Risky Biz did a killer write-up as well. Story <a href="https://news.risky.biz/risky-biz-news-feds-seize-breachforums-again/">here</a>.</p></li><li><p><strong><a href="https://www.404media.co/cyber-official-speaks-out-reveals-mobile-network-attacks-in-u-s/">Cyber Official Speaks Out, Reveals Mobile Network Attacks in U.S.</a> (404 Media)</strong> - Mobile spying and tracking revealed by a whistleblower. If only I had a complete account to read it. Stupid paywall.</p></li><li><p><strong><a href="https://krebsonsecurity.com/2024/05/how-did-authorities-identify-the-alleged-lockbit-boss">How Did Authorities Identify the Alleged Lockbit Boss? </a>(Krebs on Security) - </strong>Krebs breaks down exactly how Dmitry Yuryevich Khoroshev was tracked and caught. Crazy good research.</p></li><li><p><strong><a href="https://chamath.substack.com/p/2023-annual-letter">Social Capital 2023 Annual Letter</a> (Cahamath Palihapitiya)</strong> - This annual letter details learnings, observations, and reflections on technology, economic, and creator trends. Good read!</p></li><li><p><strong><a href="https://permiso.io/blog/unmasking-adversary-cloud-defense-evasion-strategies-modify-cloud-compute-infrastructure-part-1">Unmasking adversary cloud defense evasion strategies: modify cloud computer infrastructure Part I </a>(Permiso) </strong>- Super technical cloud based attack techniques blog. Digging this one for its &#8220;light technical reading.&#8221; Good stuff!</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (5/12/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-efd</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-efd</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 12 May 2024 19:21:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/btDi70kpyic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m finally home after a long week of RSA Conference madness. The announcements were amazing, the keynotes inspiring, and the expo hall &#8230; well, that left a bit to be desired. Walking into the hall, I felt an overwhelming feeling of &#8220;beige.&#8221; By that, I mean that pretty much all the messaging on the booths was eerily the same. I feel like we&#8217;ve moved into an era of cybersecurity where the technology differences are so overlapping and grey that you can&#8217;t possibly stand out amongst the noise and not paint yourself into an awkward positioning corner. With that said, a few of the companies&#8217; messaging was clear and concise and talked about something innovative, and those few companies gave me a bit of hope for the future.</p><p>In this week&#8217;s The Cyber Why we cover the CISA Secure By Design Pledge, WIZ raising a BILLION bucks and actually having a real need for it, AI cybersecurity moves from Palo Alto and Crowdstrike, a throwback to 2003 Trustworthy Computing Memo from Microsoft, and a chuckle filled video from Matthew Broderick. All this and more in this week&#8217;s The Cyber Why!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_PqR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_PqR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 424w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 848w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1272w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png" width="176" height="176" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a619c5b1-8707-4692-9005-145b9c3da303_500x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:176,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Cyber Why | Tyler Shields | Substack&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Cyber Why | Tyler Shields | Substack" title="The Cyber Why | Tyler Shields | Substack" srcset="https://substackcdn.com/image/fetch/$s_!_PqR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 424w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 848w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1272w, https://substackcdn.com/image/fetch/$s_!_PqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa619c5b1-8707-4692-9005-145b9c3da303_500x500.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>Sponsor The Cyber Why!</strong></p><p>The Cyber Why reaches nearly 5,000 cybersecurity, technology, and investing professionals per send. With over 30,000 views a week, our content is frequently in front of your target audience. Reach out to The Cyber Why to find out how you can drive leads and brand recognition for your business. Sponsorship packages are available. <a href="https://www.thecyberwhy.com/p/sponsorships-with-the-cyber-why">Click HERE for more information.</a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe and SMASH the like button.. or something.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>CISA Secure By Design Pledge - YAY or NAY?</h2><p><strong><a href="https://www.cisa.gov/news-events/news/cisa-announces-secure-design-commitments-leading-technology-providers">CISA Announces Secure by Design Commitments from Leading Technology Providers</a> (CISA)<br><a href="https://www.cisa.gov/securebydesign/pledge/statements-of-support">Statements of Support for the Secure by Design Pledge </a>(CISA)<br><a href="https://lcamtuf.substack.com/p/im-not-cheerleading-for-the-cisa">I'm not cheerleading for the CISA pledge</a> (<a href="https://lcamtuf.substack.com/">lcamtuf&#8217;s thing</a>)</strong></p><p>This week, the Cybersecurity and Infrastructure Security Agency (CISA) announced a &#8220;Secure by Design pledge&#8221;. The pledge is voluntary for enterprise software products and services, in line with CISA&#8217;s secure-by-design principles. Many companies have taken up the torch and made public statements of support, including Armis, Cisco, Cloudflare, GitHub, Google, HP, IBM, Lenovo, Tenable, and dozens more. <strong>I love the idea of a pledge, but it won&#8217;t actually make anything better in the long run.</strong> If it was as easy as declaring &#8220;we are going to be secure,&#8221; we would have done it long ago. At first, I thought this was just another piece of lip service that software vendors were putting forward, but the article by &#8220;lcamtuf&#8221; made me see it differently. For many software companies, this may be how they get out in front of what could be coming down the pipe in the form of legal requirements containing teeth.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Finally, a REAL Reason to Raise $1B</h2><p><strong><a href="https://www.crn.com/news/security/2024/wiz-lands-1b-in-funding-12b-valuation-amid-surging-cloud-security-growth">Wiz Lands $1B In Funding, $12B Valuation Amid Surging Cloud Security Growth</a> (CRN)</strong></p><p>When I think WIZ&#8217;s growth rate can&#8217;t increase any faster, they go and pull something like this. At the RSA Conference this week, WIZ announced a $1 billion (YES with a B!) investment from major silicon valley VCs, including Andreessen Horowitz. I typically am pretty cynical when I see announcements of raising funds of this size. We live in a world where it takes way less capital to build a technology and software startup than ever, yet I keep seeing massive infusions of cash into companies that are blitzscaling markets that may not need to be blitzscaled. HOWEVER&#8230; On this particular piece of news, I think it&#8217;s imperative that WIZ bring this large amount of funding to bear. They are currently in a war with Palo Alto Networks, Crowdstrike, and others to become one of just a few major platforms that large enterprises will look to purchase. This battle is the final epic scene of the tale of cybersecurity consolidation that is upon us. The raise puts significant funds into WIZ&#8217;s war chest, allowing them to make acquisitions as they continue to broaden their product portfolio and prepare to go public. Also, they had a pretty crazy kickass booth at RSA this week - the sucker couldn&#8217;t have been cheap!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wljb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wljb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 424w, https://substackcdn.com/image/fetch/$s_!wljb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 848w, https://substackcdn.com/image/fetch/$s_!wljb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 1272w, https://substackcdn.com/image/fetch/$s_!wljb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wljb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png" width="611" height="458" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:458,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;20 Coolest Cybersecurity Products At RSAC 2024&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="20 Coolest Cybersecurity Products At RSAC 2024" title="20 Coolest Cybersecurity Products At RSAC 2024" srcset="https://substackcdn.com/image/fetch/$s_!wljb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 424w, https://substackcdn.com/image/fetch/$s_!wljb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 848w, https://substackcdn.com/image/fetch/$s_!wljb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 1272w, https://substackcdn.com/image/fetch/$s_!wljb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2faef147-f4d2-494a-8344-fbd20d2e5696_611x458.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>The AI Cyber Platform Wars Heat Up</h2><p><strong><a href="https://finance.yahoo.com/news/sentinelone-unveils-future-autonomous-security-130000730.html">INSERTING and REPLACING SentinelOne&#174; Unveils Future of Autonomous Security</a> (Yahoo Finance)<br><a href="https://www.investors.com/news/technology/palo-alto-stock-panw-makes-artificial-intelligence-push-at-rsa-conference/">Palo Alto Makes Artificial Intelligence Push At RSA Conference </a>(Investor Business Daily)<br><a href="https://www.paloaltonetworks.com/company/press/2024/palo-alto-networks-launches-new-security-solutions-infused-with-precision-ai-to-defend-against-advanced-threats-and-safeguard-ai-adoption">Palo Alto Networks Launches New Security Solutions Infused with Precision AI to Defend Against Advanced Threats and Safeguard AI Adoption</a> (Palo Alto Website)</strong></p><p>The cyber AI platform wars have begun. Last week at RSA, I had the pleasure of sitting in on the announcement by Palo Alto Networks of their new Precision AI  cybersecurity solutions, three distinct platforms, and connected co-pilots. It was an exciting presentation in which Palo Alto clearly depicted how they plan to leverage their industry-leading broad set of data and context to provide preventative security solutions ranging from code all the way to cloud-native operational security. Also last week, SentinelOne announced their future of autonomous security built on the back of their Singularity Data Lake and Purple AI system. While Palo has a much broader approach today, it appears that the first battleground will be where AI and security operations collide. Improvements in the SOC are the &#8220;low hanging fruit&#8221; in which these cybersecurity behemoths can have a massive impact quickly. Over time, AI will stretch to broader solution sets and value propositions. I plan to follow these two companies, as well as Microsoft, Google, Wiz, and a few others, very closely as this new AI cybersecurity reality emerges.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Trustworthy Computing 2.0</h2><p><strong><a href="https://www.theverge.com/24148033/satya-nadella-microsoft-security-memo">Read Satya Nadella&#8217;s Microsoft memo on putting security first</a> (The Verge)<br><a href="https://en.wikipedia.org/wiki/Trustworthy_computing">Trustworthy Computing</a> (Wikipedia)<br><a href="https://www.techradar.com/pro/security/microsoft-is-tying-executive-pay-to-security-performance-so-if-it-gets-hacked-no-bonuses-for-anyone">Microsoft is tying executive pay to security performance &#8212; so if it gets hacked, no bonuses for anyone</a> (TechRadar)</strong></p><p>I&#8217;m guessing many of you aren&#8217;t old enough to remember the famous email of 2002 from Bill Gates to every Microsoft employee announcing the <a href="https://www.microsoft.com/en-us/security/blog/2022/01/21/celebrating-20-years-of-trustworthy-computing/">&#8220;Trustworthy Computing (TWC) Initiative.&#8221;</a> In the years leading up to the 2002 memo, attackers and security researchers had been making a complete mockery of Microsoft and the security of their software and products. There were significant customer breaches, product vulnerabilities weaponized, and, quite frankly, Microsoft became the laughing stock of cybersecurity. We reminisced about the initiative in the most recent <a href="https://www.thecyberwhy.com/p/tcw-big-heads-laceworks-deal-sisense?initial_medium=video">The Cyber Why Podcast</a> as we covered the Cyber Safety Review Board Report on Microsoft and <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4ac0fb06-ca31-4031-b771-baf3ec53bd46_679x679.jpeg&quot;,&quot;uuid&quot;:&quot;eea59eb9-b888-48f7-b862-bec7eee3b951&quot;}" data-component-name="MentionToDOM"></span> even broke down some of the issues in a <a href="https://www.thecyberwhy.com/p/a-meta-review-of-the-summer-2023">TCW Deep Thought piece</a> on the topic. When we think we have seen another new low for Microsoft, they pop up and take a page from Bill Gates&#8217; old playbook from 2003. Satya Nadella, Microsoft CEO, sent out his own version of the Trustworthy Computing Memo to over 200K employees. Suppose they put the same effort behind the new initiative as Gates and their team did in 2002. In that case, we should see Microsoft become a more secure and hopefully dominant player in the cybersecurity space. Good luck, Microsoft - it&#8217;s a tough hill to climb!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-efd?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-efd?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>I &lt;3 Matthew Broderick and Wargames!</h2><p><strong><a href="https://www.cnet.com/tech/services-and-software/cybersecurity-ai-and-ted-lasso-what-weve-seen-at-the-rsa-conference/">Cybersecurity, AI and Alicia Keys: What We've Seen at the RSA Conference</a> (CNET)</strong></p><p>What do Ted Lasso, Alicia Keys, Matthew Broderick, Homeland Security Secretary Alejandro Mayorkas, and Secretary of State Antony Blinken all have in common - absolutely NOTHING except that they were all at the RSA 2024 conference as speakers or keynotes. While I&#8217;m not sure why a couple of those names were chosen (Alicia Keys, she&#8217;s fantastic, but what&#8217;s the connection to cyber?), most speakers were perfect for content and inspiration. Some videos can be found on the official <a href="https://www.youtube.com/@RSAConference">RSA Conference YouTube Channel</a>; others are available as bootleg shots, like the Matthew Broderick one below. I loved this video as Wargames was a HUGE influence on me. If you have free time, look at the content - you&#8217;ll be sufficiently inspired. </p><div id="youtube2-btDi70kpyic" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;btDi70kpyic&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/btDi70kpyic?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://stiennon.substack.com/p/palo-alto-networks-abdicates">Palo Alto Networks Abdicates</a> (The Security Industry) - </strong>Richard, do you have a vendetta against PANW? First, you snipe them for their 2024 strategy; then, you snipe them for pulling out of RSA. A major conference like RSA provides a vendor with both demand generation and brand awareness. When you are a massive company like PANW, you already have both in large quantities, making guerilla marketing a potentially smart move. Alternatively, if you are a tiny company, it also makes sense to go rogue due to ROI metrics when nobody knows your name and your tiny reach. I disagree with you on this one - PANW pulling out of RSA and doing their own thing is just the start of many major companies moving to run their own side conferences during that same week.</p></li><li><p><strong><a href="https://www.linkedin.com/pulse/free-advice-economy-josh-bernoff-mrdmc/">The free advice economy; 500-foot baguette; 40,000 robot narrators</a> (Josh Bernoff) - </strong>Great brief article on why I give free advice to others. tl;dr, I get self-reward from it, and hopefully, they find value in it! This is how the world operates.</p></li><li><p><strong><a href="https://www.crn.com/news/security/2024/akamai-doubles-down-on-api-security-with-450m-noname-acquisition-deal">Akamai Doubles Down On API Security With $450M Noname Acquisition Deal</a> (CRN) </strong>- Bargain basement acquisition prices are here. Akamai snaps up NoName.</p></li><li><p><strong><a href="https://www.scmagazine.com/perspective/note-to-investors-and-security-pros-drive-innovation-by-going-on-the-offensive">Note to investors and security pros: drive innovation by going on the offensive</a> &nbsp;(SC Media) - </strong>Bob Ackerman on driving innovation with offensive moves. A great investor with great advice. Must read.</p></li><li><p><strong><a href="https://www.wired.com/story/lockbitsupp-lockbit-ransomware/">The Alleged LockBit Ransomware Mastermind Has Been Identified</a> (WIRED)</strong> - With eyes like his, I would have pegged him for a criminal overlord from a mile away. Either that or as someone who has to tell his neighbors that he just moved in.</p></li><li><p><strong><a href="https://www.hackread.com/intelbroker-hacker-cybersecurity-firm-breach/#google_vignette">IntelBroker Hacker Claims Breach of Top Cybersecurity Firm, Selling Access</a> (Hack Read)</strong> - No proof yet, but where there is smoke, there&#8217;s typically fire. Watch this one closely, as I bet it breaks further over the next two weeks.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (5/3/24)]]></description><link>https://www.thecyberwhy.com/p/tcw-050324</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/tcw-050324</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 03 May 2024 20:16:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>T-Minus three days to RSA! It&#8217;s time to pack up the swag and datasheets and b-line straight out to Moscone Center for the annual schmoozefest called the RSA Conference. Several members of The Cyber Why team will be there handing out stickers and other swag items, so please grab one of us and say hello! </p><p>In this week&#8217;s TCW, we wax eloquent regarding the 2024 RSA Innovation Sandbox finalists, get depressed thanks to the 17th DBIR report where nothing got better, debate the natural fit between Aqua (water) and Orca (whales), watch as a Darktrace short gets slapped back to reality, and finally talk about Tyler&#8217;s FAT HEAD! All this and more in this weekly The Cyber Why!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe and follow - we need all the positive affirmation we can get!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h2>RSAC Innovation Sandbox 2024 Cohort</h2><p><strong><a href="https://pulse.latio.tech/p/latio-pulse-rsac-innovation-sandbox-watch">RSAC Innovation Sandbox 2024 - Who to Watch</a> ([Latio Pulse] )</strong></p><p>The RSA Conference is just a few days away! Hot press releases, venture funding, acquisition rumors, and product announcements have been flooding the newswire. It&#8217;s the time of year that some of us loathe (introverts unite), and many of us cherish (extroverts, I don&#8217;t understand you!). It&#8217;s a time to analyze where cybersecurity is headed, readdress our strategy and trends, meet up with old friends, and make some new ones as well. One of the hottest discussion items each year at RSA is the Innovation Sandbox finalists. These companies are supposed to be the most innovative, unique, and compelling product offerings in their rookie class. Some go on to become massive publicly traded companies, and many sell for hundreds of millions of dollars to the highest bidder. Either way, it&#8217;s a time when analysis of these companies makes a lot of sense and is something we should at least take a glance at.</p><p>This year, the companies fall into the following general categories: Identity Innovation, Generative AI Security, Cloud and Kubernetes Security, and Exploit Intelligence. The biggest thing about each of these companies is that their products and technology are unique, elevating them above the category confusion that plagues the rest of the cybersecurity startup world. Good luck to this cohort&#8230; it&#8217;s going to be fun to watch you grow up!</p><ul><li><p><a href="https://aembit.io/">Aembit</a> - Secure Machine-to-Machine Token Authentication</p></li><li><p><a href="https://p0.dev/">P0 Security</a> - Just In Time (JIT) Access to APIs, Workloads, and Infrastructure</p></li><li><p><a href="https://www.harmonic.security/">Harmonic</a> - Generative AI Data Security</p></li><li><p><a href="https://www.antimatter.io/">Antimatter</a> -  Generative AI Security</p></li><li><p><a href="https://rad.security/">Rad Security</a> - Kubernetes Security and Cloud Native Threat Detection and Response</p></li><li><p><a href="https://vulncheck.com/">VulnCheck</a> - Exploit Intelligence for Vulnerability Prioritization</p></li><li><p><a href="https://www.antimatter.io/">Antimatter</a> - Make data safe for GenAI, fast!</p></li><li><p><a href="https://www.bedrock.security/">Bedrock Security</a> - Frictionless Data Security</p></li><li><p><a href="https://www.realitydefender.com/">Reality Defender</a> - Detect Generative AI Threats</p></li><li><p><a href="https://www.dropzone.ai/">Dropzone.AI</a> - AI SOC Analyst</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aP37!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aP37!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 424w, https://substackcdn.com/image/fetch/$s_!aP37!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 848w, https://substackcdn.com/image/fetch/$s_!aP37!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 1272w, https://substackcdn.com/image/fetch/$s_!aP37!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aP37!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png" width="225" height="225" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26a1294f-e844-4094-a464-7126d3b096e4_225x225.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:225,&quot;width&quot;:225,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;RAD Security Selected as Finalist for ...&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="RAD Security Selected as Finalist for ..." title="RAD Security Selected as Finalist for ..." srcset="https://substackcdn.com/image/fetch/$s_!aP37!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 424w, https://substackcdn.com/image/fetch/$s_!aP37!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 848w, https://substackcdn.com/image/fetch/$s_!aP37!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 1272w, https://substackcdn.com/image/fetch/$s_!aP37!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a1294f-e844-4094-a464-7126d3b096e4_225x225.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Tyler&#8217;s Verizon DBIR Depression Kicks In</h2><p><strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/verizon-dbir-basic-security-gaffes-underpin-bumper-crop-of-breaches">Verizon DBIR: Basic Security Gaffes Underpin Bumper Crop of Breaches</a> (Dark Reading)<br><a href="https://www.scmagazine.com/news/verizons-2024-data-breach-investigations-report-5-key-takeaways">Verizon&#8217;s 2024 Data Breach Investigations Report: 5 key takeaways</a> (SC Media)<br><a href="https://www.verizon.com/business/resources/reports/dbir/">2024 Data Breach Investigations Report DBIR</a> (Verizon)</strong></p><p>This report is one of my favorite reports of the year - yet I&#8217;ve stopped reading it cover to cover. It&#8217;s not because of a lack of available time that I have given up on the content. Instead, it&#8217;s a lack of hope. Maybe this is where my jaded old cyber personality comes out. In the last 17 years of analyzing the DBIR I have seen next to ZERO improvement in the state of cybersecurity. Sure, the goalposts of success have moved, the weapons chosen by the adversaries have changed, and the defensive models have advanced, but in actuality, we are no better off today than we were a decade and a half ago. Please comment below if you are more hopeful about the future of cybersecurity and help me see that a positive future can exist (hit the comments below). In the meantime, here are some of the interesting statistics that jumped out to me in this year&#8217;s report:</p><ul><li><p>Primarily thanks to the MoveIT attack, vulnerabilities as the first entry point jumped 180% year over year. Attackers can weaponize their attacks rapidly, making them highly successful.</p></li><li><p>MoveIT accounted for 8%  of all reported breaches. </p></li><li><p>Extortion attempts occurred in 32% of all reported breaches. The average loss was $46K per successful breach.</p></li><li><p>The average time to remediate a 0-day is 55 days. The average time to weaponize a new vulnerability is five days. That&#8217;s nearly TWO MONTHS of exploitability window, assuming everyone fixes their issues on day one. That&#8217;s BAD!</p></li><li><p>68% of breaches involve a "non-malicious human element"&#8212;phishing, misconfiguration, or other human mistakes. To quote the great T. Swift&#8230;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kcm_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kcm_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kcm_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png" width="588" height="308.7" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:588,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;It's Me. I'm the Problem.. Taylor Swift, female leadership &amp;&#8230; | by Martha  Tatarnic | Medium&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="It's Me. I'm the Problem.. Taylor Swift, female leadership &amp;&#8230; | by Martha  Tatarnic | Medium" title="It's Me. I'm the Problem.. Taylor Swift, female leadership &amp;&#8230; | by Martha  Tatarnic | Medium" srcset="https://substackcdn.com/image/fetch/$s_!Kcm_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Kcm_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dcc65d6-c050-4c8a-989d-bb6c22b2662d_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Two Formidable Companies Join Forces to Fight Cloud Workload Compromise</h2><p><strong>Integrating Aqua Security with the Orca Cloud Security Platform (<a href="https://orca.security/resources/blog/integrating-aqua-security-with-orca-platform/?utm_source=substack&amp;utm_medium=email">Orca Security</a>)</strong></p><p>(<em>Katie pick</em>) I saw this coming, and I think it&#8217;s <em>big. </em>These are two powerhouse companies working together to identify and remediate cloud-based compromise in near real-time. With this integration, Orca and Aqua are knocking down the common arguments against each other&#8217;s tech approach: &#8220;Agents can&#8217;t see where they&#8217;re not deployed.&#8221; &#8220;Agentless technologies can&#8217;t see into the workload.&#8221; </p><p>These arguments are used by vendor sales teams all the time, depending on which side of the agent vs. agentless fence they sit on. The reality of any networking is that security teams need both. Without the ability to monitor and control endpoints and the ability to monitor and control traffic, blind spots will remain. </p><p>This integration &#8212; and similar ones in the future &#8212; could threaten cybersecurity asset management (CAM) companies if they&#8217;re not careful. I know (as well as anyone) that the message from CAM is, &#8220;We aggregate data from these tools and more.&#8221; While true, Orca and Aqua have the capital and the brand recognition to spin the narrative in their direction and secure tightening budgets &#8212; especially because cloud compromise is something CEOs are being warned about. </p><p>Aqua and Orca have repeatedly proven themselves; this looks like it will be a big win for end users. And I wouldn&#8217;t be surprised to see an acquisition in the near future. </p><p><em>Editors Note: Is it me, or are Oracs and Aqua totally meant to be together?</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Shorting Darktrace Seemed Brilliant. Until It Didn&#8217;t.</h2><p><strong><a href="https://www.reuters.com/markets/deals/thoma-bravo-buy-uks-darktrace-about-532-billion-2024-04-26/">Thoma Bravo to buy UK's Darktrace for around $5.3 bln</a> (Reuters)</strong></p><p><em>(Adrian Pick)</em> I think there&#8217;s a lesson here. In my part of the cybersecurity industry, Darktrace is a bit of a joke. I don&#8217;t think I&#8217;ve ever encountered someone happy with the product. It seemed clear that it was a small amount of tech (open source, at that), with a lot of window dressing around it. Shades of FireEye.</p><p>With the Thoma Bravo take private announcement, suddenly, we were all second-guessing ourselves. Were we wrong about them? Is everything Darktrace marketing has been claiming - the digital immune system stuff - is all that validated now?</p><p>It&#8217;s not an enormous win, but a solid one - Thoma Bravo&#8217;s offer is ~8x on 2023 revenue. FireEye (after it split from Mandiant) exited at a steeply declining 1.2x to Trellix. It makes me wonder how much of a shock this has been for the folks at Quintessential Capital Management, who released a scathing report on Darktrace just over a year ago and announced they were shorting it. If we assume QCM was shorting DARK when they published this report, DARK was around 250 pence on the LSE. After the announcement from Thoma Bravo, DARK leaped from ~450 up to 600 pence. Ouch.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eXDC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eXDC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 424w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 848w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 1272w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eXDC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png" width="522" height="320.67644521138914" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:712,&quot;width&quot;:1159,&quot;resizeWidth&quot;:522,&quot;bytes&quot;:89866,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eXDC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 424w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 848w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 1272w, https://substackcdn.com/image/fetch/$s_!eXDC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3b42752-2144-470b-9e5f-3580bb3d09ed_1159x712.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/tcw-050324?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/tcw-050324?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Republicans have FAT HEATS! &lt;/clickbait&gt;</h2><p><strong><a href="https://gizmodo.com/ai-can-tell-your-political-affiliation-just-by-looking-1851430714">AI Can Tell Your Political Affiliation Just by Looking at Your Face, Researchers Find </a>(Gizmodo)</strong></p><p>This most definitely qualifies as a story #5. As you know, #5s are supposed to be funny, irreverent, quirky, or just downright weird. This particular story falls into the downright weird bucket. Recent research has shown that just by looking at a person&#8217;s still and emotionless face, AI can accurately predict if you are a liberal or a conservative. WTF?! Apparently, the researchers had this to say:</p><blockquote><p>According to this analysis&#8212;and, I have to warn you, it&#8217;s kinda funny&#8212;liberals and conservatives have markedly different facial morphology. Liberals have &#8220;smaller lower faces&#8221; and &#8220;lips and noses [that] are shifted downward,&#8221; and chins that &#8220;are smaller&#8221; than conservatives, researchers write. Researchers repeat the key conclusion later on: &#8220;liberals tended to have smaller faces.&#8221;</p><p>So, according to this theory, if you have a tiny face, you&#8217;re probably a progressive. Or, by contrast, if you have a big fat face, there&#8217;s a good chance you might be a Trump voter.</p></blockquote><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-NU0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-NU0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 424w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 848w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 1272w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-NU0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png" width="468" height="272.3205574912892" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:1148,&quot;resizeWidth&quot;:468,&quot;bytes&quot;:820087,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-NU0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 424w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 848w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 1272w, https://substackcdn.com/image/fetch/$s_!-NU0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5c8fcd3-bd51-4128-84e6-c774d7bc9075_1148x668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">TCW Editor Tyler with his BIG FAT HEAD!</figcaption></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.tenable.com/blog/tenable-bolsters-its-cloud-security-arsenal-with-malware-detection">Tenable Bolsters Its Cloud Security Arsenal with Malware Detection</a> (Tenable BLog) - </strong>And the water gets murkier! Tenable adds CNAPP-style capabilities, including malware detection in workload, to its stable of technologies. The centers of gravity are getting closer day by day!</p></li><li><p><strong><a href="https://techcrunch.com/2024/05/02/microsoft-bans-u-s-police-departments-azure-openai-facial-recognition/">Microsoft bans US police departments from using enterprise AI tool for facial recognition</a> (TechCrunch) </strong>- This could end up being controversial. When the risks of AI impacting privacy become &#8220;good for the general population,&#8221; we are going to have explosive debates. Watch this one over the next few years.</p></li><li><p><strong><a href="https://www.bloomberg.com/news/articles/2024-05-02/apple-s-110-billion-stock-buyback-plan-is-largest-in-us-history?embedded-checkout=true">Apple&#8217;s $110 Billion Stock Buyback Plan Is Largest in US History</a> (Bloomberg) - </strong>It&#8217;s usually a good sign when a company believes enough in themselves to buy back shares. Watch $APPL closely as it moves into the second half of 2024.</p></li><li><p><strong><a href="https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/examining-the-deception-infrastructure-in-place-behind-code/ba-p/4124464">Examining the Deception infrastructure in place behind code.microsoft.com</a> (Microsoft Blog)</strong> - For over 2 years code.microsoft.com has been a honeypot! The data they collected was incredibly useful to MS and the community at large.</p></li><li><p><strong><a href="https://danielmiessler.com/p/ul-429#ideas-analysis">Harvesting Ideas from Questionable People </a>(Dan Meissler) </strong>- This resonated with me. Everyone should read this and evaluate how they perceive others and the world and how they are able to learn while maintaining their own moral code.</p></li><li><p><strong><a href="https://softwareanalyst.substack.com/p/the-future-of-soc-automation-platforms">The Future of SOC Automation Platforms</a> (Francis Odum) -</strong> A great report on the modernization of the SOC and the technology stack to go with the updated processes. This research should also be reproduced for Appsec, Cloudsec, Infrasec, and all other *Sec derivatives).</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (4/26/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-f1c</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-f1c</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 26 Apr 2024 22:01:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There were WAY too many incredible stories to cover them all this week. Due to the volume, I even had to leave off half a dozen from the quick hits list. There is so much awesomeness to discuss that we&#8217;ve decided to bring a chunk of it over to The Cyber Why POD. We&#8217;re recording the latest episode of the podcast this weekend, and it is scheduled to go live on our <a href="https://www.thecyberwhy.com/podcast">podcast link</a> by the end of the week! We&#8217;ll talk about the best stories of the last 30 days, including some of the big ones you see here! Remember to subscribe to <a href="https://www.thecyberwhy.com/podcast">The Cyber Why podcast</a> on your favorite podcast tool (we&#8217;re on all of the good ones!) Now, onto this week&#8217;s newsletter.</p><p>This week in The Cyber Why, we cover the latest updates to the gift that keeps on giving news: the United Healthcare Group hack. We discuss the impact of the non-compete ban in the United States and take aim at building companies just to get rich. We provide a feedback loop on Iranian phishing attempts, and finally, we put a new gift on Tyler&#8217;s birthday wishlist &#8212; a flame-throwing robot dog (I want one SO BAD!). All this and more in this week&#8217;s The Cyber Why!</p><div><hr></div><p><strong><a href="https://www.thecyberwhy.com/p/sponsorships-with-the-cyber-why">Sponsor The Cyber Why - Reach Nearly 5,000 Tech and Cyber Leaders TODAY!</a></strong></p><p>The Cyber Why is your weekly dose of cybersecurity wit straight to your inbox. TCW tracks cyber and tech news and drama with humor you won't find anywhere else. Sponsor TCW and reach thousands of active subscribers bi-weekly. Don't be a phish, sponsor today! </p><p><a href="https://www.thecyberwhy.com/p/sponsorships-with-the-cyber-why">CLICK HERE</a> or email tyler dot shields at gmail.com for sponsorship specifics.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Please go to the GoFundMe page to help Tyler get a robot flamethrowing dog!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h2>UHG Update - Admits To Having Paid Ransom</h2><p><strong><a href="https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-updates-on-change-healthcare-cyberattack.html">UnitedHealth Group Updates on Change Healthcare Cyberattack</a> (United Health Group)<br><a href="https://www.cbsnews.com/news/unitedhealth-ransom-paid-change-healthcare-attack/">UnitedHealth paid ransom after massive Change Healthcare cyberattack </a>(CBS News)<br><a href="https://www.csoonline.com/article/2094609/authentication-failure-blamed-for-change-healthcare-ransomware-attack.html">Authentication failure blamed for Change Healthcare ransomware attack</a> (CSO)<br><a href="https://www.reuters.com/business/healthcare-pharmaceuticals/unitedhealth-ceo-testify-before-us-house-panel-cyberattack-tech-unit-2024-04-19/">UnitedHealth CEO to testify before US House panel on cyberattack at tech unit </a>(Reuters)</strong></p><p><em>(Rick Pick) </em>It was a significant news week for updates on the Change Healthcare extortion attack. UnitedHealth Group (UHG) issued a press release with less-than-encouraging news on Monday. The company said that it:</p><blockquote><p><em><strong>"has found files containing protected health information (PHI) or personally identifiable information (PII), which could cover a substantial proportion of people in America."</strong></em> </p></blockquote><p>There are over 335 million Americans, and the release substantially understates the potential implications. Later that night, a spokesperson told CBS News that the company paid a ransom ($22M) to the extortionists (ALPHV). The company revealed "$872 million in unfavorable cyber attack effects in its <a href="https://www.unitedhealthgroup.com/content/dam/UHG/PDF/investors/2024/UNH-Q1-2024-Release.pdf.">release</a>." </p><p>What would a favorable cyberattack effect be? <em>Asking for a friend.</em> It was also reported that "compromised credentials on an application" is how the attackers gained their initial access.</p><p>You could debate me, but this could be a top-three ransomware attack, especially considering potential future losses. It demonstrates the fragility of our interdependent systems and begs the question, where is the next Change Healthcare? What other sectors have their version of this type of target? Finally, if compromised creds on an "MFA-less" application were the initial access vector, it highlights that actors don't need esoteric zero-day to achieve their goals. Companies need to be maniacal about managing their external footprints and hardening their external services. UHG's CEO, Andrew Witty, is testifying on The Hill next week; get your popcorn ready.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>I&#8217;m Now Dating Your Best Friend - HOW YA LIKE ME NOW!</h2><p><strong><a href="https://www.npr.org/2024/04/23/1246655366/ftc-bans-noncompete-agreements-lina-khan">U.S. bans non-compete agreements for nearly all jobs </a>(NPR)</strong></p><p>One of this week's hottest topics, the FTC ban on non-compete agreements in the United States, brought on a flurry of news articles, pundit commentary, and debate about whether non-compete agreements are essential to safeguard a business. In some circles (employee slack groups specifically), the commentary was all rainbows and unicorns talking about how bad non-competes were, and while commonly known to be unenforceable in most states, how they still acted as a deterrent to changing jobs since most companies wouldn&#8217;t hire you if you signed a non-compete agreement for fear of being sued by your former overlords. </p><p>In some tech founder groups, the commentary wasn&#8217;t so appreciative of the moves made by the FTC. Some founders said that if people could move freely to competition, it would make it more difficult to keep human resources and increase the cost of doing business. They also suggested that it would bring about a significant amount of IP theft and brain drain from one company to another in a similar space. In general, I don&#8217;t believe that non-competes should be allowed. However, I see the potential impact that can occur to businesses with no better way to defend themselves from nefarious individuals willing to act maliciously. Let me know how you feel about the topic in the comments below! </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Founder Syndrome in Cybersecurity </h2><p><strong><a href="https://ventureinsecurity.net/p/in-2024-finding-cybersecurity-startup">In 2024, finding cybersecurity startup ideas worth pursuing is harder than many people think</a> (Venture in Security)</strong></p><p>(<em>Katie pick</em>) As Ross writes in his latest piece, &#8220;Starting a cybersecurity startup is easier than ever,&#8221; but that doesn&#8217;t mean the industry needs more startups or that founders and would-be founders are starting cyber vendor companies for the right reasons.</p><p>As I&#8217;ve written in the past (<a href="https://thereformedanalyst.substack.com/p/why-starting-a-business-for-a-big">part 1</a>; <a href="https://thereformedanalyst.substack.com/p/cybersecurity-vendor-success">part 2</a>), there are plenty of headwinds to founding a cybersecurity business, which Ross expertly outlines in his article. What he doesn&#8217;t touch on is what I&#8217;ll call &#8220;founder syndrome,&#8221; or the idea that &#8220;there is a gap in X aspect of security. I&#8217;ll build this widget. I&#8217;ll sell this widget. I&#8217;ll get rich and create the world&#8217;s biggest cybersecurity company.&#8221; Building a cybersecurity technology with the idea of &#8220;getting rich&#8221; rarely results in achieving the goal. You&#8217;d be better served just buying state-run lottery tickets!</p><p>Building a security company from scratch is a mighty endeavor, even for tenured founders. This piece covers many of the considerations that entrepreneurs should ask themselves&#8212;and their investors&#8212;before entering the fray. Don&#8217;t just throw caution to the wind and hang a shingle - know what you are getting yourself into.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!45CE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!45CE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!45CE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!45CE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!45CE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!45CE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg" width="286" height="286" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1445,&quot;width&quot;:1445,&quot;resizeWidth&quot;:286,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;PREMIUM Startup Founders \&quot;I'M A BROKE STARTUP FOUNDE\&quot; Hoodie&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="PREMIUM Startup Founders &quot;I'M A BROKE STARTUP FOUNDE&quot; Hoodie" title="PREMIUM Startup Founders &quot;I'M A BROKE STARTUP FOUNDE&quot; Hoodie" srcset="https://substackcdn.com/image/fetch/$s_!45CE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 424w, https://substackcdn.com/image/fetch/$s_!45CE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 848w, https://substackcdn.com/image/fetch/$s_!45CE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!45CE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbec309-2c55-44a2-a849-6f8d1ee3c777_1445x1445.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Iranian Attackers Go Phishing</h2><p><strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/iran-dupes-military-contractors-govt-agencies-cybercampaign">Iran Dupes US Military Contractors, Gov&#8217;t Agencies in Years-Long Cyber Campaign </a>(Dark Reading)</strong></p><p>(<em>Katie pick</em>) While the US government has been busy issuing cybersecurity guidance for public and private sectors, it seems that they, themselves, are not immune to social engineering attacks. </p><p>The Fed recently announced that &#8220;hundreds of thousands&#8221; of US business and government employees were the target of Iranian state-sponsored cyber espionage campaigns between 2016-2021. Four Iranian nationals were indicted but are unlikely to face any real charges due to extradition laws.</p><p>While the article claims the attackers were &#8220;clever&#8221; and &#8220;more sophisticated by a significant margin,&#8221; the tactics employed seem straightforward &#8212; masquerading as a cybersecurity services provider and asking targets to click on links. You know the rest of the story. The story's moral here isn&#8217;t &#8220;Haha, the government got tricked, too!&#8221; Instead, the moral is: <em>We must focus on security basics that help limit attack escalation</em>. Social engineering works and will continue to work until someone can build a solution that stops the malware from executing and stops the attackers from elevating privileges after the link has been clicked. We&#8217;re not going to stop link-clicking &#8212; we all need it for everyday, non-malicious business &#8212; so let&#8217;s look at the compensating controls. And get them right.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w-zu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w-zu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w-zu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg" width="264" height="264" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:264,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Did You Click the Link? &#8211; Information Technology Services&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Did You Click the Link? &#8211; Information Technology Services" title="Did You Click the Link? &#8211; Information Technology Services" srcset="https://substackcdn.com/image/fetch/$s_!w-zu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w-zu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072758ca-58f0-4eb2-97e6-19ab97972a05_500x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-f1c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-f1c?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Tyler&#8217;s Updated Birthday Wish List</h2><p><strong><a href="https://news.yahoo.com/tech/flamethrowing-robot-dog-shoot-fire-130140930.html">Watch: Fire-breathing robot dog that can torch anything in its path</a> (Yahoo)</strong></p><p>This is the thing that nightmares are made of! Robot dogs with flamethrowers on their backs. It reminds me of Austin Powers talking about &#8220;sharks with fricken LASERS on their heads!&#8221; As if that wasn&#8217;t scary enough. These little 1ft square beauties are manufactured by the US firm Throwflame, can eject fuel for up to 45 minutes, and can be purchased by the general public in the United States of Freaking America for only 7,600 British Pounds. Shoots 30-foot jets of fire, remotely controlled and enabled with laser sight and a built-in flashlight, this bringer of mayhem looks too good to pass up! Time to get my checkbook out! Or better yet - I&#8217;ll start a GoFundMe for my next birthday present&#8230; it&#8217;s just around the corner.</p><div id="youtube2-U83BfU1phCw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;U83BfU1phCw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/U83BfU1phCw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.linkedin.com/posts/boxaaron_ai-agents-have-the-potential-to-democratize-activity-7188981400774086657-sIst/">Aaron Levie, CEO at Box on AI Agents Impact On Business</a> (LinkedIn) - </strong>Aaron is one smart dude. He equates AI agents to the advent of SaaS, detailing the potential massive market impact.</p></li><li><p><strong><a href="https://www.calcalistech.com/ctechnews/article/hjkhycoga">Wiz CTO: &#8220;AI is probably the fastest-adopted technology in history&#8221;</a> (Calcalist) </strong>- This time with data to back the assertion. WOW... incredible pace of change.</p></li><li><p><strong><a href="https://www.scalevp.com/insights/a-world-after-wiz-emerging-opportunities-in-cloud-security/">A world after Wiz: Emerging opportunities in cloud security </a>(Scale VP) - </strong>While we are on the topic of Wiz. What&#8217;s a world post-Wiz look like for cybersecurity companies? Where&#8217;s the whitespace for the next crop of Israeli startups?</p></li><li><p><strong><a href="https://www.linkedin.com/posts/colegrolmus_the-biggest-question-from-noname-securitys-activity-7185652347891503105-gEwd/">Is NoName the normal exit size now?</a> (Cole Grolmus)</strong> - Lots to unpack here. Strategic products and companies can still exit but nowhere near as big as they once could. Down rounds abound!</p></li><li><p><strong><a href="https://franklyspeaking.substack.com/p/the-wiz-acquisition-of-lacework-makes">The Wiz acquisition of Lacework makes sense</a> (Frankly Speaking)</strong> - PHEW, at least I&#8217;m not the only one that thinks this way. I thought I was on an island here!\</p></li><li><p><strong><a href="https://resilientcyber.substack.com/p/the-rise-of-application-security">The Rise Of Application Security Posture Management (ASPM) Platforms </a>(Chris Hughes)</strong> - Sorry, buddy. Let&#8217;s agree to disagree on this one. ASPM is just another token product that will get absorbed into something bigger. </p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (4/19/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-3ee</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-3ee</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Sun, 21 Apr 2024 20:19:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This week in TCW: Altitude Cyber drops it&#8217;s Q1 2024 state of cybersecurity market report and it&#8217;s a MUST READ. We throw a flash bang into the room and suggest that fixing 0-day flaws, while required, doesn&#8217;t really move the needle and we take a dive into the &#8220;security data fabric&#8221; that is the brick and morter of AI-driven cyber. We offer a bit of unfiltered self help discussion (always a fan favorite), and finally debate the concept of AI generated TV and what it will mean to society at large. All that and I even use the word en-shitification this week in The Cyber Why! </p><div><hr></div><p><strong><a href="https://www.thecyberwhy.com/p/sponsorships-with-the-cyber-why">Sponsor The Cyber Why - Reach Nearly 5,000 Tech and Cyber Leaders TODAY!</a></strong></p><p>The Cyber Why is your weekly dose of cybersecurity wit straight to your inbox. TCW tracks cyber and tech news and drama with humor you won't find anywhere else. Sponsor TCW and reach thousands of active subscribers bi-weekly. Don't be a phish, sponsor today! </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to TCW and I will personally thank you when we meet face to face!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h2>Top Market Report - MUST READ, 5+ STARS</h2><p><strong><a href="https://drive.google.com/file/d/16d1T95AXHBfH8pm96b3lZHkXudV-q14R/edit">Q1 2024 Cybersecurity Market Review</a> (Altitude Cyber)</strong></p><p>One of the most robust cybersecurity market analysis reports dropped this week. Dino Boukouris and the team at Altitude Cyber provide for your reading please the <em><strong>Q1 2024 Cybersecurity Market Review Report</strong></em>. The overall themes and takeaways include a positive uptick in cybersecurity deal making, a larger than normal rate of major M&amp;A activities, and even later stage financing is making a comeback. This report takes a look at all of the moves being made in cybersecurity including calling out some of the top companies that made the RSA Innocation Sandbox for 2024. Go take a look at the entire list but I&#8217;d like to directly hype up a couple of my favorites, specifically <a href="https://rad.security/">RAD Security</a> and <a href="https://vulncheck.com/">Vulncheck</a>. These two companies provide interesting and unique value propositions to their customers that really can&#8217;t be found anywhere else - and that&#8217;s saying something in today&#8217;s overly crowded product landscape. Finally, here are a couple of my favorite chart from the report - I HIGHLY recommend you load this article up and at a minimum look through all of the amazing pictures!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zq5m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zq5m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 424w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 848w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 1272w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zq5m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:516906,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zq5m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 424w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 848w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 1272w, https://substackcdn.com/image/fetch/$s_!Zq5m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2add1aea-04dd-40a9-a2c0-facc859280c1_2798x1572.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cybersecurity M&amp;A Trends from Altitude Cyber Report Q1 2024</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f8IL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f8IL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 424w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 848w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 1272w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f8IL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png" width="1456" height="822" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:822,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:442262,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f8IL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 424w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 848w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 1272w, https://substackcdn.com/image/fetch/$s_!f8IL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcd75d2-4d17-4bdb-9441-02eff8db98b8_2792x1576.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cybersecurity Financing Trends from Altitude Cyber Report Q1 2024</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>0-Day Vulnerabilities - Do They REALLY Matter?</h2><p><strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/cisco-duo-multifactor-authentication-service-breached">Cisco Duo's Multifactor Authentication Service Breached</a> (Dark Reading)<br><a href="https://news.risky.biz/risky-biz-news-putty-crypto-bug-exposes-private-keys-may-lead-to-supply-chain-attacks/?ref=risky-business-news-newsletter">PuTTY crypto bug exposes private keys, may lead to supply chain attacks </a>(Risky Biz News)<br><a href="https://thehackernews.com/2024/04/palo-alto-networks-discloses-more.html">Palo Alto Networks Discloses More Details on Critical PAN-OS Flaw Under Attack </a>(The Hackers News)<br><a href="https://hackaday.com/2024/04/19/this-week-in-security-putty-keys-libarchive-and-palo-alto/">This week in security: Putty keys, libarchive, and Palo Alto</a> (Hackaday)</strong></p><p>Maybe it&#8217;s a function of my age. Maybe I am just a jaded old security guy who has been around the scene too long to worry about issues such as these any more. Don&#8217;t get me wrong &#8212; the PAN-OS bug is seeing active exploitation, the Putty flaw opens up all sorts of crypto risk, and Cisco&#8217;s Duo problem could certainly lead to major issues at enterprises world wide. However, I no longer get excited when the latest 0-day drops and everyone flies into a risk induced tizzy. I guess the vibe really comes from the fact that as an industry, cybersecurity still can&#8217;t handle the low hanging fruit let alone have the capability and resources to mitigate the risk that comes from some crazy advanced crypto issue or a supply chain risk that compromised some very important data. Maybe I&#8217;m analyzing this completely the wrong way (highly likely!) I guess I&#8217;m looking for more root cause fixes as opposed to bandaids that solve a point in time problem such as the latest vulnerabilities.</p><p>Someone out there please help me get back to the time when finding new vulnerabilities was interesting and that solving these problems really did make the world a better place. Right now I feel like it&#8217;s similar to shooting down a massive drone attack with a single slingshot. You might get one or two but you certainly won&#8217;t stop the onslaught. Put your discussion comments below&#8230;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tHg0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tHg0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tHg0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg" width="311" height="311" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:311,&quot;width&quot;:311,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Oh, you have an opinion on 0day? I'm sure you know best from your years of  exploit development - Condescending Wonka - quickmeme&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Oh, you have an opinion on 0day? I'm sure you know best from your years of  exploit development - Condescending Wonka - quickmeme" title="Oh, you have an opinion on 0day? I'm sure you know best from your years of  exploit development - Condescending Wonka - quickmeme" srcset="https://substackcdn.com/image/fetch/$s_!tHg0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tHg0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bbc5008-5281-4b17-936e-3556c2334e89_311x311.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Once Upon a Security Data Fabric</h2><p><strong><a href="https://www.cybersecuritypulse.net/p/the-security-data-fabric-shift-explained">The Security Data Fabric Shift Explained: Why Zscaler Paid $350M for Avalor And What It Means For The Security Industry</a> (The Cybersecurity Pulse)<br><a href="https://www.thecyberwhy.com/p/palo-alto-networks-a-play-for-the">Palo Alto Networks - A Play For The Future</a> (The Cyber Why)<br><a href="https://www.thecyberwhy.com/p/the-next-era-of-cyber-security-capabilities">The Next Era of Cyber Security Capabilities</a> (The Cyber Why)</strong></p><p>As we progress through 2024, large public cybersecurity behemoths are all triangulating to the next era of cybersecurity offerings. I&#8217;ve written about this topic several times over the last year, most recently in the abovementioned pieces. This week, <a href="https://www.cybersecuritypulse.net/p/the-security-data-fabric-shift-explained">Darwin Salazar wrote a great piece about ZScaler's acquisition of Avalor</a>. His commentary echoes my views almost identically regarding the AI-backed cybersecurity future being painted by Palo Alto Networks, Crowdstrike, Cisco/Splunk, and now ZScaler. Large-scale, contextual, data-driven, AI-analyzed cybersecurity platforms are coming, and they will be glorious! Darwin did a great job summarizing the impact of the Avalor acquisition in the quote below. Read the original article for additional deep-thought specifics.</p><blockquote><p>In the past couple of years, we&#8217;ve seen vendors double down on contextualizing security issues, because without context, everything is seemingly on fire all the time and security teams struggle with deciding what to prioritize. I&#8217;m a firm believer that Wiz has eaten much of PANWs market share due to their attack path analysis and other contextual features. Without data infra to support cross-pollination of data sources, it&#8217;s nearly impossible to add context to security issues. This is why the Avalor acquisition gives Zscaler an upper hand in the near-term.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Your Self-Help Corner of the Week</h2><p><strong><a href="https://www.forbes.com/sites/janicemarturano/2024/04/15/stop-searching-for-worklife-balancewhats-important-is-to-be-present/?sh=521e6714334d">Stop Searching For Work/Life Balance- What&#8217;s Important Is To Be Present </a>(Forbes)</strong></p><p>I don&#8217;t usually include content around work/life balance, mental health, and recommendations on remaining present in a chaotic and busy world. However, when I do, I almost always get positive feedback from the audience. I wonder if the nature of what we do as cybersecurity people makes this type of discussion more difficult and simultaneously more needed. For this particular summary, it doesn&#8217;t matter why these kinds of articles resonate as long as you find a sliver of information you can learn from and hopefully improve with. The info-nugget I walked away with from this article was a potential reframing of the concept of work/life balance. The author is indirectly incepting the idea that attempting to balance your work and personal life may not be the best option for your mental health. It might be more of a function of remaining present in every moment that can bring happiness to the breadth of activities that must be accomplished on any given day. </p><p>Whether you need better balance or are learning the ability to be happy with the imbalance of your current life, this article provides a few ideas on how to achieve a better state of being. Enjoy and namast&#233;!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-3ee?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-3ee?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>AI Generated Pure Trash TV</h2><p><strong><a href="https://www.404media.co/email/b58c3b61-d77d-434e-ba64-645e5524f799/?ref=daily-stories-newsletter">The Dystopian Future of TV Is AI-Generated Garbage</a> (404 Media)</strong></p><p>The <em><strong>en-shitification</strong></em> of television content has begun. I don&#8217;t know if this type of garbage qualifies as television anymore. After reading the article, I am not even convinced that television as a media will exist in even remotely the same way once AI has its way with the content. In a nutshell AI-generated content is beginning to take over the streaming media space and appears to be dumbing down the value while shooting out pure garbage in a volume attempt at success. Although, I have to admit I don&#8217;t think AI generated garbage content could get quite as bad as the latest season of Keeping Up With The Kardashians.. I mean that is pure trash TV and it&#8217;s &#8220;real&#8221;.</p><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://www.reviewjournal.com/business/casinos-gaming/mgm-resorts-sues-ftc-agency-chair-over-cyberattack-investigation-3034150/">MGM Resorts sues FTC, agency chair over cyberattack investigation</a> (Las Vegas Review-Journal) - </strong>MGM sued the FTC because the FTC commissioner was on MGM's property during the attack, making her a witness, not a prosecution leader. That just got spicey!</p></li><li><p><strong><a href="https://resilientcyber.substack.com/p/you-cant-teach-someone-to-swim-when">You can't teach someone to swim when they're drowning </a>(Resilient Cyber). </strong>Chris Hughes does it again with his take on secure by design and why it&#8217;s important &#8220;by the numbers.&#8221;</p></li><li><p><strong><a href="https://www.cnbc.com/2024/04/18/cisco-debuts-new-ai-focused-cybersecurity-system-after-splunk-deal.html">Cisco debuts new AI-focused security system after $28 billion deal to buy Splunk</a> (CNBC) - </strong>Cisco and Splunk team up to launch HyperShield. Their attempt to remain relevant in the new cyber-AI era. I&#8217;m not buying this one yet.</p></li><li><p><strong><a href="https://www.cnn.com/2024/04/18/tech/labhost-cybercrime-phishing-arrests/index.html">Police take down $249-a-month global phishing service used by 2,000 hackers </a>(CNN) - </strong>2000+ hackers sign up for your illicit services, and the most you can get is 1.5M$. Sounds like bad business to me. Too much risk for not enough reward.</p></li><li><p><strong><a href="https://ventureinsecurity.net/p/building-platforms-in-cybersecurity">Building platforms in cybersecurity: select playbooks for growing &#8220;best of suite&#8221; solutions</a> (Venture in Security)</strong> - <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ross Haleliuk&quot;,&quot;id&quot;:2607604,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa0e73b-27de-49eb-a585-393f1add9ab8_1500x1000.jpeg&quot;,&quot;uuid&quot;:&quot;2eff5bcb-4367-4993-b87b-33a5d26e169f&quot;}" data-component-name="MentionToDOM"></span> does it again. Great piece from Ross on build vs buy and other difficulties in platform building in Cyber.</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (4/12/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-671</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-671</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 12 Apr 2024 19:52:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It&#8217;s a beautiful spring day here, and I admit I&#8217;m as happy as a dog in the sun. This week, we have an incredible slate of technology and security stories for your consumption. The breaches and vulns keep rolling in, with Sisense, PANW, and LastPass all making the content cut. We also discuss the impact of CAC and churn on SaaS business models and the meaningfulness (or not) of cyber catastrophes. Last but not least, we delve into modern money laundering and the efficacy of a public and private relationship to fix NVD. Don&#8217;t forget to check out <a href="https://www.thecyberwhy.com/podcast">The Cyber Why Podcast</a> and see the TCW team in living color! Have a great weekend!</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VPZ1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VPZ1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 424w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 848w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 1272w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VPZ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png" width="330" height="201.31715771230503" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:704,&quot;width&quot;:1154,&quot;resizeWidth&quot;:330,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Traceable Blog: Learn API Security Best Practices - Traceable API Security&quot;,&quot;title&quot;:&quot;Traceable Blog: Learn API Security Best Practices - Traceable API Security&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Traceable Blog: Learn API Security Best Practices - Traceable API Security" title="Traceable Blog: Learn API Security Best Practices - Traceable API Security" srcset="https://substackcdn.com/image/fetch/$s_!VPZ1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 424w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 848w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 1272w, https://substackcdn.com/image/fetch/$s_!VPZ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F942028cd-f4d6-41ca-b308-54f67614528f_1154x704.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><em><strong>Featured Sponsor - Traceable.AI</strong></em></p><p><strong><a href="https://www.traceable.ai/resources/lp/webinar-masterclass-ep4?utm_source=cyberwhy">API Masterclass Episode 4 is LAUNCHED!</a></strong></p><p>Do you love the idea of robbing a bank? Good news, you can, totally ethically. Join Traceable for the next live API Security Masterclass. We&#8217;ll cover an introduction to APIs, what kinds of vulnerabilities exist, how to find them, and how to test your own APIs. Whether you&#8217;re on the blue team and trying to understand threats, a hacker new to APIs, or a developer trying to better understand how your code can go wrong, these live classes will tell you everything you need to know. And don&#8217;t leave it on in the background, these are interactive sessions so you can get the most out of it! Join <a href="https://www.traceable.ai/resources/lp/webinar-masterclass-ep4?utm_source=cyberwhy">Episode 4</a> or go back to <a href="https://www.traceable.ai/resources/lp/webinar-api-security-masterclass?utm_source=cyberwhy">Episode 1</a> to get caught up!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you like what you read, please click subscribe. It&#8217;s 100% free (payment optional)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Sisense Breach Fallout Will Be BIG!</h2><p><strong><a href="https://krebsonsecurity.com/2024/04/why-cisa-is-warning-cisos-about-a-breach-at-sisense/">Why CISA is Warning CISOs About a Breach at Sisense</a> (Krebs on Security)<br><a href="https://vulnu.mattjay.com/p/sinense-breach">Matt Johansen Writeup on Sisense breach</a> (Vulnerable U)<br><a href="https://news.risky.biz/risky-biz-news-sisense-breach-has-cisa-and-everyone-else-panicking/">Sisense breach has CISA and everyone else panicking</a> (Risky Biz News)</strong></p><p>This one is going to be a big one. Krebs and others have done some detailed research on the massive security breach at Sisense. I didn&#8217;t know what Sisense was until I read about this breach, and after I heard what they did, the importance of the issue jumped. Sisense is a product and application business intelligence platform that allows you to make smarter decisions based on real data from your products. The attackers discovered cloud tokens, allowing them to access Sisense customer data, which included &#8220;millions of access tokens, email account passwords, and even SSL certificates.&#8221; The result of the attack is a massive compromise that may lead to the compromise of over 1000 customers&#8217; downstream systems and applications. In short, this is a big one! It&#8217;s so big, in fact, that CISA themselves have begun reaching out to potentially compromised companies to facilitate cleanup and lower the risk of additional fallout.</p><p><em><strong>If you use Sisense or have any upstream or downstream vendors that use Sisense, please ensure you read these details and respond as quickly as possible. You are at risk.</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>How Churn Destroys SaaS Models - OUCH!</h2><p><strong><a href="https://www.onlycfo.io/p/is-saas-math-broken">Is SaaS Math Broken</a> (OnlyCFOs)<br><a href="https://www.thecyberwhy.com/p/the-margin-crush-is-coming-in-2024">The Margin Crush is Coming in 2024</a> (The Cyber Why)</strong></p><p>As an adjunct professor at a major business school (Go Heels!), I stay very connected with business economics. This particular article is relevant not only for general SaaS  behavioral knowledge but is specifically important for cybersecurity founders and investors to understand. As your customer acquisition costs (CAC) increase and your time to pay back those costs after you land a customer (CAC payback) gets longer, the unit economics of SaaS businesses break down. Add to that, the most frequent issue I&#8217;m seeing in cyber SaaS companies today - a massive increase in churn - and you have a recipe for disaster. In the next five years, AI will decrease the amount of time it takes to build newer, updated technologies, increasing churn and lengthening CAC Payback times for cyber SaaS solutions. This raises the real question: &#8220;What happens next?&#8221; If <a href="https://www.thecyberwhy.com/p/the-margin-crush-is-coming-in-2024">SaaS margins go down</a>, churn goes up, and CAC Payback gets out of control, will there be enough efficiency gains in traditional SaaS business models to offset those impacts? Time will tell&#8230; in the meantime, go read this article and nerd out on metrics for a bit.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MrbR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MrbR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MrbR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg" width="378" height="260.0769230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:644,&quot;width&quot;:936,&quot;resizeWidth&quot;:378,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A Founders Guide to Churn. Churn is probably one of the most&#8230; | by Ventures  Platform | Medium&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A Founders Guide to Churn. Churn is probably one of the most&#8230; | by Ventures  Platform | Medium" title="A Founders Guide to Churn. Churn is probably one of the most&#8230; | by Ventures  Platform | Medium" srcset="https://substackcdn.com/image/fetch/$s_!MrbR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MrbR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5afc0711-9b29-4cef-9272-77d1b4ef0832_936x644.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Is A Private + Public NVD a Good Idea?</h2><p><strong><a href="https://securityboulevard.com/2024/04/nist-proposes-public-private-group-to-help-with-nvd-backlog/amp/">NIST Proposes Public-Private Group to Help with NVD Backlog</a> (Security Boulevard)</strong></p><p>As we previously discussed in The Cyber Why, The National Institute of Standards and Technology (NIST) is facing severe challenges with its National Vulnerability Database (NVD) as it struggles to keep up with a surge in security vulnerabilities due to budget cuts and increased software vulnerabilities. Instead of adequately funding the problem, NIST is now proposing the creation of a public-private consortium to help tackle the backlog. This consortium would include stakeholders from industry, government, and other sectors to collaborate on improving the NVD's efficiency and coverage.</p><p>The situation at NIST and the NVD backlog is at a critical juncture. The NVD is an essential tool that informs threat intelligence and vulnerability management, helping to prioritize and mitigate potential threats. With the backlog growing, timely and reliable data becomes scarce, potentially exposing systems to unaddressed vulnerabilities. What concerns me the most is the potentially perverse incentive structures if a joint NIST and private sector effort were to happen. The private sector will always attempt to make a profit and bias the work effort to help them do so. Because of this, the results may not be as broadly suited to the improved security of the world. Instead, it may benefit a few companies that can successfully leverage a return on time and resource investment. I&#8217;ll be watching this one closely.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Are Cyber Catastrophes Meaningful?</h2><p><strong><a href="https://bindinghook.com/articles-binding-edge/debunking-notpetyas-cyber-catastrophe-myth/">Debunking NotPetya&#8217;s cyber catastrophe myth </a>(Binding Hook)</strong></p><p>What if the risk of a massive cyber attack or worm really wasn&#8217;t that massive? The author of this article draws comparisons of the most significant cyber catastrophes of all time against natural disasters and other massive financially impacting black swan incidents. I&#8217;m not 100% convinced of his logic as he attempts to normalize the dollar impacts of attacks, including NotPetya, The Morris Worm, SoBig, MyDoom, and others, against wars, famine, hurricanes, and other naturally occurring disasters. </p><p>I&#8217;m not sure what the analysis's benefit is other than to tell cybersecurity people not to take themselves so seriously. In the grand scheme of things, a massive cyber attack that impacts the majority of the world isn&#8217;t going to be important twenty years from now. The author says, &#8220;It&#8217;s just not big enough to matter.&#8221; As technology continues to embed itself into the day-to-day lives of society, the impact of disruption and attack will continue to increase in significance. When an attack takes down a hospital that impacts the life of a loved one, it&#8217;s going to matter to you, too! Let&#8217;s take this one to the notes section - I&#8217;d love to hear what you think of the author&#8217;s conclusions!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-671?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-671?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Money Laundering in the Modern Age</h2><p><strong>How a Money Laundering Crew Allegedly Moved Millions Through FanDuel (404 Media)</strong></p><p>It's not quite a &#8220;story #5&#8221;, but it's still an interesting departure from the standard attacks and defenses type of content. This article, while a little bit short on technical details  and rightfully so, digs into a modern money laundering scheme using the latest online sports betting apps such as DraftKings and FanDuel. It&#8217;s a long-known fact that nefarious activities happen around casinos, and money laundering is one of them. Now that those casinos are prolific throughout the United States and online, I&#8217;m certain that we will see continued growth in these types of fraud-based attacks. Hackers go where the money is, and right now, the money is in and around the online betting systems. Give this one a read, and if you want to bet on these attacks' growth, hit me with a comment below &lt;GRIN&gt;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C63Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C63Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 424w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 848w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C63Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg" width="259" height="194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:194,&quot;width&quot;:259,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;NFL Memes - &#128514; | Facebook&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="NFL Memes - &#128514; | Facebook" title="NFL Memes - &#128514; | Facebook" srcset="https://substackcdn.com/image/fetch/$s_!C63Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 424w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 848w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!C63Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17ef8ea-20f5-4a62-8253-f798057c641a_259x194.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><strong><a href="https://cybernews.com/security/cybersecurity-for-100-bucks-cyber-pros/">The $100 cybersecurity budget &#8211; how cyber pros would spend it</a> (CyberNews) - </strong>Might as well be $0, but the thought experiment is an exciting idea.</p></li><li><p><strong><a href="https://thesecuritypath.com/">The Security Path - New Book Announcement</a></strong> - I was interviewed by two great authors and participated in this fun, new book detailing how successful cyber notables got to where they are today. Use code &#8220;<em>thecyberwhy</em>&#8221; for a 40% discount when purchasing!</p></li><li><p><strong><a href="https://www.theverge.com/2024/4/6/24122915/openai-youtube-transcripts-gpt-4-training-data-google">OpenAI transcribed over a million hours of YouTube videos to train GPT-4 </a>(The Verge)</strong> - We all knew they did it, but what does it mean to fair use and copyright legal precedent? Time will tell.</p></li><li><p><strong><a href="https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/amp/">LastPass: Hackers targeted employee in failed deepfake CEO call</a> (Bleeping Computer) - </strong>We knew this was coming. Eventually, attackers will stop using weird comms channels, and this attack class will work like a charm.</p></li><li><p><strong><a href="https://security.paloaltonetworks.com/CVE-2024-3400">CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway</a> (Palo Alto Networks) </strong>- A critical OS command injection vulnerability in the GlobalProtect Gateway of Palo Alto Networks PAN-OS software for specific versions. Patches coming soon!</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Why: What We Read This Week...]]></title><description><![CDATA[... and why you should too! (4/5/24)]]></description><link>https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-410</link><guid isPermaLink="false">https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-410</guid><dc:creator><![CDATA[Tyler Shields]]></dc:creator><pubDate>Fri, 05 Apr 2024 19:51:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There are days when TCW wouldn&#8217;t be possible without the fantastic team of analysts who helped me create the weekly content. This week would be one of those rough weeks. I sit here in Louisville airport with a tear of appreciation in my eye for the TCW staff. Thanks, guys. I owe you one this time around.</p><p>In this week's TCW, we cover a scathing cyber safety review board report lambasting Microsoft, AI&#8217;s impact on the impending elections, the long con that is the XZ Utils supply chain hack, NIST rewarding people entering the cyber field, and a cloud of magic security dust that solves all of your cyber theater issues! All this and more in this week&#8217;s edition of The Cyber Why!</p><div><hr></div><p><em><strong>Featured Sponsor - Material Security </strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vN47!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vN47!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!vN47!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!vN47!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!vN47!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vN47!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png" width="370" height="145.09803921568627" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1020,&quot;resizeWidth&quot;:370,&quot;bytes&quot;:9785,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vN47!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 424w, https://substackcdn.com/image/fetch/$s_!vN47!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 848w, https://substackcdn.com/image/fetch/$s_!vN47!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 1272w, https://substackcdn.com/image/fetch/$s_!vN47!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c5cc9f3-72ee-44e5-9dd8-59017a2bbece_1020x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><a href="https://material.security/phishing-protection?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240404-the-cyber-why">Are you wasting your email security budget?</a></p><p>When every dollar counts, you want to make sure you make the most of what you get. You (hopefully) get funds for anti-phishing tools, but the threat landscape extends beyond the inbox.</p><p>With more sophisticated attack flavors at higher volumes than ever, email security must also encompass insider risk scenarios, account takeover protection, and data loss prevention.</p><p>See why <a href="https://material.security/phishing-protection?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240404-the-cyber-why">Material Security</a> is the preferred choice for organizations looking to protect more areas of their Microsoft 365 or Google Workspace footprint under a unified toolkit&#8230; and a single line item in the budget.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://material.security/phishing-protection?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240404-the-cyber-why&quot;,&quot;text&quot;:&quot;Visit Material Security&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://material.security/phishing-protection?utm_source=third-party&amp;utm_medium=email&amp;utm_campaign=20240404-the-cyber-why"><span>Visit Material Security</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Your subscriptions keep us going! Subscribe here for FREE!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qlP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4393,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qlP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!3qlP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779b6892-0d05-4719-9ce5-5cb52ba88216_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Microsoft's "Secure Future Initiative" Isn&#8217;t Looking So &#8220;Secure&#8221;</h2><p><strong><a href="https://www.cisa.gov/resources-tools/resources/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer-2023">Cyber Safety Review Board Releases Report on Microsoft Online Exchange Incident from Summer 2023</a> (CISA)<br><a href="https://apnews.com/article/microsoft-cybersecurity-hack-raimondo-breach-b0901a93cca2ffaf05edacbfb9ecf3da">Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack</a> (AP) </strong></p><p><em>(Rick Pick)</em> This week, the <a href="https://www.cisa.gov/resources-tools/groups/cyber-safety-review-board-csrb">Cyber Safety Review Board </a>released a scathing report regarding Microsoft's 2023 Exchange Online breach. Although we could dissect the 29-page report separately, here's an overview of the crucial points. A Chinese-based threat actor, Storm-0558, gained unfettered access to the email accounts of a broad range of victims across the US, UK, and beyond. The threat actor has ties back to 2009's <a href="https://googleblog.blogspot.com/2010/01/new-approach-to-china.html">Operation Aurora</a>, targeting Google. The Board wrote: </p><blockquote><p>"identified a series of Microsoft operational and strategic decisions that collectively point to a corporate culture that deprioritized both enterprise security investments and rigorous risk management."  </p></blockquote><p>Microsoft was disingenuous when it claimed that the actor gained access via a crash dump, no evidence was provided to support this. </p><blockquote><p>"Microsoft has not identified a crash dump that contains the 2016 MSA key, or any other evidence of the key having been moved inappropriately." </p></blockquote><p>It took six months for Microsoft to update its blog, and only after the Board's persistence. Most alarming, Microsoft is still unaware of how the threat actor gained access to the MSA key. The Board wrote:</p><blockquote><p>"The loss of a signing key is a serious problem, but the loss of a signing key through unknown means is far more significant because it means that the victim company does not know how its systems were infiltrated and whether the relevant vulnerabilities have been closed off." </p></blockquote><p><strong>The "Findings and Recommendations" section is a must-read for enterprises and vendors alike. One final note: vendors who live in glass houses shouldn't throw stones. Some folks who compete against Microsoft's cybersecurity products have been quick to judge. I'd look at the twenty-five recommendations and ensure my own house is in order, especially if you are a "platform" player that makes for an attractive target to nation-state actors.</strong></p><p><em>Editor&#8217;s (Tyler) Note: Hot damn, this is a good take. We can all go a long way to improve before we start throwing stones at our opponents. Great write-up, Rick!</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N9fw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N9fw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!N9fw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ab4fb3b-4bdb-468c-9f47-a52cc5d37643_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>AI Will Play a Pivotal Role in U.S. Elections</h2><p><strong><a href="https://blogs.microsoft.com/on-the-issues/2024/04/04/china-ai-influence-elections-mtac-cybersecurity/">China tests US voter fault lines and ramps AI content to boost its geopolitical interests</a> (Microsoft blog)<br><a href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/MTAC-East-Asia-Report.pdf">Same targets, new playbooks: East Asia threat actors employ unique methods </a>(Microsoft)<br><a href="https://www.theguardian.com/technology/2024/apr/05/china-using-ai-disrupt-elections">China will use AI to disrupt elections in the US, South Korea and India, Microsoft warns</a> (The Guardian)</strong></p><p>(<em>Katie Pick</em>) A new report from the Microsoft Threat Intelligence division says that the Chinese Communist Party (CCP)- and North Korean-affiliated actors are testing AI-aided techniques to influence elections in the U.S. and abroad. The research group has been looking into trends and indicators since June 2023. It states that these adversarial nation-state actors focus on the South Pacific Islands, regional Chinese adversaries, and the U.S. defense industrial base.</p><p>Interference in U.S. elections is always a hot topic, and it&#8217;s not unexpected that China (or other adversaries) would try to disrupt or influence the upcoming U.S. Presidential election. Mis- and disinformation are rampant around election time, and reports show that voters consuming information on specific social media platforms are likely to be <a href="https://www.sciencedirect.com/science/article/abs/pii/S0740624X23000102">swayed by malicious content</a>.</p><p>With recent advancements in AI, threat actors can more easily create deep fakes, highly convincingly manipulated images and videos, and other AI-enhanced content. Microsoft previously released research on how the Chinese use generative AI to &#8220;create sleek, engaging visual content.&#8221; Now, says the tech firm, China is doubling down on publication. </p><p>Though social media platforms say they&#8217;ll do their part to identify, remove, and/or block maliciously manipulated content, only time will tell if they&#8217;re successful. Humans are prone to influence, and everybody loves a juicy story about their most hated presidential candidate. AI will make it harder to spot and stop the &#8220;fake news.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wpG6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wpG6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!wpG6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9686f08a-bbff-45b9-8146-2c0d55eaddec_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>XZ Utils, The Mother Of All Backdoors, Almost  </h2><p><strong><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4">Backdoor in upstream xz/liblzma leading to ssh server compromise</a> (Andres Freund)<br><a href="https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/">What we know about the xz Utils backdoor that almost infected the world </a>(Ars Technica) <br><a href="https://www.wired.com/story/jia-tan-xz-backdoor/">The Mystery of &#8216;Jia Tan,&#8217; the XZ Backdoor Mastermind</a> (WIRED)</strong></p><p>This could be one of the most drama-filled stories of the year. A severe security breach recently occurred within the XZ Utils project, a popular data compression tool for Linux systems. Hackers cleverly embedded a backdoor into specific versions of the software. If exploited, this backdoor could provide attackers with complete remote control of vulnerable systems, allowing them to bypass authentication on servers using those compromised versions.</p><p>The incident reinforces the critical need for strict security measures in open-source projects and highlights the dangers of software supply chain attacks. Security experts are still working to identify the culprits behind the attack, with the latest theories centering on a foreign nation-state actor who has been executing a slow and low attack for years. In application security circles, it&#8217;s often discussed how easy it would be to spend a decade or more to build up a reputation as a conscientious contributor to open-source projects only to embed something nefarious years into the project. It seems like we weren&#8217;t the only ones considering this exact threat scenario.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://twitter.com/fr0gger_/status/1774342248437813525/photo/1" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!efVU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!efVU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!efVU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!efVU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!efVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg" width="540" height="755.8516483516484" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2038,&quot;width&quot;:1456,&quot;resizeWidth&quot;:540,&quot;bytes&quot;:541133,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://twitter.com/fr0gger_/status/1774342248437813525/photo/1&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!efVU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!efVU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!efVU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!efVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bf19468-d3da-419d-a228-6661fc4e45b4_1463x2048.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em><strong>Thanks to the great <a href="https://twitter.com/fr0gger_">Thomas Roccia</a> for putting this graphic together:</strong></em> </figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-iqM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-iqM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!-iqM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b212c8-d003-4755-9aa2-a11c32fb0262_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>A NICE Cybersecurity Workforce Development Program Aimed at Bringing New Talent to the Field</h2><p><strong><a href="https://www.nist.gov/news-events/news/2024/04/nist-awards-36-million-community-based-cybersecurity-workforce-development">NIST Awards $3.6 Million for Community-Based Cybersecurity Workforce Development</a> (NIST)</strong></p><p>(<em>Katie pick</em>) On April 3, 2024, the National Institute of Standards and Technology (NIST) announced the 18 organizations to which it has pledged funding to help with cybersecurity workforce development and recruitment. The grants, of up to $200,000 each, were awarded to diverse education and community organizations across 15 U.S. states. </p><p>Anyone who has worked in the space knows about the legendary &#8220;talent shortage&#8221; faced by both private and public organizations. As companies&#8217; rapid tech adoption fuels the need for increased security measures and governance, already-stretched security teams struggle to handle the amount of work on any given day.</p><p>The funding offered by NIST and delivered in collaboration with <a href="https://www.nist.gov/itl/applied-cybersecurity/nice">NICE</a> will help train and educate individuals interested in cybersecurity careers. NIST is still accepting applications for future grants through Friday, May 24, 2024. Participants can learn more about the program on <a href="https://www.nist.gov/news-events/news/2024/03/ramp-your-program-apply-cybersecurity-education-and-workforce-development">NIST&#8217;s website</a>. A free informational webinar will be held on April 8, 2024 at 3 PM ET.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-410?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecyberwhy.com/p/the-cyber-why-what-we-read-this-week-410?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tYcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png" width="100" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tYcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 424w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 848w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1272w, https://substackcdn.com/image/fetch/$s_!tYcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb523b666-bd81-4b4e-955b-af6e9f915acb_100x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Finally a Product That Solves Security Theater</h2><p><a href="https://agilestationery.com/products/magic-security-dust-by-adam-shostack">Magic Security Dust&#8482; from Shostack + Associates</a> (Adam Shostack)</p><p>In a world where most of the products we purchase to help secure our environments are built on the backs of unicorn tears and fairy wishes, a product that fixes everything is finally launched. I announce to you -  &#8220;MAGIC SECURITY DUST!&#8221; Just sprinkle a little on all of those broken products, procedures, policies, and even PEOPLE, and before you know it, your cyber security program turns from theater to reality! Check out this fantastic solution brought to you by the threat modeling expert himself, Adam Shostack. Date of launch: April 1, 2024!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R1n6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R1n6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R1n6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg" width="376" height="403.8901098901099" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1564,&quot;width&quot;:1456,&quot;resizeWidth&quot;:376,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R1n6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 424w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 848w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!R1n6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa10563b4-b592-4dae-afb2-4920d0a53265_2623x2817.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Quick Hits  and Hidden Gems</h2><ul><li><p><a href="https://www.prnewswire.com/news-releases/rsa-conference-releases-finalists-for-rsac-innovation-sandbox-contest-2024-302105044.html">RSA Conference Innovation Sandbox Contest Finalists Announced</a> <strong>(RSAC) - </strong>If you are headed to RSAC, this is one of the best parts of the week.</p></li><li><p><strong><a href="https://www.darkreading.com/vulnerabilities-threats/nist-needs-help-digging-out-of-its-vulnerability-backlog">NIST Wants Help Digging Out of Its NVD Backlog</a> (Dark Reading)</strong> - This follows a story we did on the <a href="https://www.thecyberwhy.com/p/defcon-canceled-pay-to-play-analysts">latest TCW Podcast</a>. NIST needs help! </p></li><li><p><strong><a href="https://strategyofsecurity.com/themes-from-and-beyond-altitude-cybers-2023-cybersecurity-year-in-review/">Themes From (And Beyond) Altitude Cyber's 2023 Cybersecurity Year In Review</a> (Strategy of Security)</strong> - Themes from 13 years of cyber market research.</p></li><li><p><strong><a href="https://pmarca.substack.com/p/on-tech-politicspolicy-2-hour-video">On Tech Politics/Policy -- 2 hour video discussion</a> (</strong><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Marc Andreessen&quot;,&quot;id&quot;:22353,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8ef02fe-d089-466f-9b4a-ea19df828473_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;b6cdad37-c92e-40c7-9760-ffa0e430da5a&quot;}" data-component-name="MentionToDOM"></span>) - Two hours on tech politics and policy with one of the leading tech luminaries.</p></li><li><p><strong><a href="https://securityaffairs.com/161371/data-breach/owasp-data-breach.html">The OWASP Foundation disclosed a data breach that impacted some members due to a misconfiguration of an old Wiki web server. </a>(Security Affairs) - </strong>It&#8217;s a nothing-burger of a story but still an interesting target that y&#8217;all care about!</p></li></ul><div><hr></div><p><em>If you&#8217;ve made it this far, you either found our musings at least semi-entertaining, OR you enjoyed the pain and kept going regardless. No matter how you made it to this point, you should know that we appreciate you. Please do us a solid and share <strong>The Cyber Why</strong> with your friends. We would love to reach a bigger audience, and referrals are how we do it. Help us out, and we&#8217;ll see you next week!<br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Cyber Why&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://thecyberwhy.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Cyber Why</span></a></p>]]></content:encoded></item></channel></rss>