Browse all articles

Advisory & Planning
AI is Accelerating Exploits in 2026

In April 2026, Anthropic built a model it chose not to release. Claude Mythos Preview discovered and weaponized software vulnerabilities at machine speed, so the Anthropic team held it back and gave controlled access to roughly 50 organizations it trusted to harden their own code, among them AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, and the Linux Foundation. This unprecedented development marked a turning point in the field of AI Vulnerability Discovery. The program, called Project Glasswing, was created to provide a headstart to defenders, in hopes they could be enabled before attackers developed this capability independently. The window to...

nuHarbor June 16, 2026 ∙ 5 min read
Advisory & Planning
Two Ransomware Campaigns Your Team Needs to Know About

What Happened Two ransomware stories broke this week that deserve your attention at the same time, because together they paint a picture of where ransomware is headed. These incidents highlight a trend of increasingly sophisticated ransomware campaigns. Neither of these are new. Rather, we’re seeing an uptick in activity from both actors. The first is The Gentlemen, a newly identified ransomware family written in Go that combines fast, robust file encryption with self-propagating lateral movement across networks. Microsoft published a detailed technical breakdown on May 28 showing that The Gentlemen can spread without any human interaction once it’s inside a network,...

Justin Fimlaid June 2, 2026 ∙ 5 min read
Advisory & Planning
Public Sector Cyber Resilience: Beyond Just Security

Most public sector security teams are trying to build something that doesn't exist: an environment where nothing goes wrong. The challenge of public sector cyber resilience is to be prepared for and adapt to evolving threats rather than just aiming for perfect security. They invest in the latest tools, pass compliance audits, block thousands of threats a month, and report the numbers up the chain. Leadership hears exactly what they want to hear, “we are protected.” But that's the problem. Cybersecurity vs. Cyber Resilience: Two Different Goals Cybersecurity and cyber resilience are not the same thing. Most organizations treat them...

Kyle Smith May 19, 2026 ∙ 5 min read
Advisory & Planning
Continuous Security Monitoring is Baseline in State Governance

Picture your state's IT security team on a Tuesday afternoon. They're talented, overextended, and genuinely committed to protecting the systems that millions of constituents depend on. At 5:01 p.m., they log off. The alerts keep firing. The logs keep generating. And somewhere overseas, an adversary who cares nothing about your labor agreements is just getting started. This is not a scare tactic. It is the operational reality that compliance frameworks, state labor law, and basic threat intelligence all point toward simultaneously. When you stack the regulatory mandates on top of the workforce realities on top of the 24/7 nature of...

Justin Fimlaid May 5, 2026 ∙ 8 min read
Advisory & Planning
Iran Cyber Threats and Their Impact on Security

Why the 2025 playbook is suddenly the right playbook for 2026: One of the most concerning issues for the coming year is Iran Cyber Threats and their impact on global security. The Middle East-driven risk story going into the rest of 2026 is not “brand new cyber warfare.” It is familiar weaknesses being exploited with escalation dynamics (disruption, coercion, signaling) that look more like crisis behavior than ordinary cybercrime. An April 2026 joint advisory from the Federal Bureau of Investigation, National Security Agency, Environmental Protection Agency, Department of Energy, United States Cyber Command, and the Cybersecurity and Infrastructure Security Agency...

Justin Fimlaid April 21, 2026 ∙ 9 min read