Category: Threats & Defense

Attacker tradecraft, detection, incident response, and the tooling on both sides.

  • We Didn’t Learn from EDR. Now We’re Doing It Again with AI.

    Cybersecurity keeps making headlines — not because attackers are getting clever, but because attacks are constant, bigger, and bolder. And yet, in boardrooms and IT shops everywhere, leaders are telling themselves the same comforting lie: “We’re safe. We’ve got the tools.” A few years ago, that tool was EDR. Today, it’s AI. Both promised to…

  • Someone Is Using Your Computer Right Now. You Just Can’t See It.

    Someone Is Using Your Computer Right Now. You Just Can’t See It.

    You’re sitting at your desk. Working. Maybe on a spreadsheet. Maybe answering emails. Your screen looks normal. Your machine is running fine. Nothing feels off. And on the exact same machine, at the exact same moment, an attacker is logged into your internal systems, browsing your files, and staging their next move. Not on a…

  • Spiderman – Your Friendly Neighborhood Phishing Kit

    Spiderman – Your Friendly Neighborhood Phishing Kit

    For a long time, phishing survived because it was good enough. It didn’t need to be perfect. It just needed to catch the distracted, the rushed, or the unlucky. We were trained to look for the “tells.” Bad grammar didn’t matter to the attacker. Broken layouts didn’t matter. Even getting blocked didn’t matter, because the…

  • The Bug Is the Doorway. The Agent Is the Burglar.

    The Bug Is the Doorway. The Agent Is the Burglar.

    On March 10, 2026, Microsoft patched CVE-2026-26144. It’s an XSS bug in Excel. CVSS 7.5. On paper, medium-severity, the kind of thing that used to mean a stolen session cookie and a compliance ticket. This one doesn’t steal cookies. A malicious payload embedded in a spreadsheet fires when Excel renders it, hijacks Copilot Agent, and…

  • The Threat Below the Operating System: What Almost Nobody Understands About Rootkits

    The Threat Below the Operating System: What Almost Nobody Understands About Rootkits

    Your antivirus didn’t find it. Your EDR didn’t flag it. Your IT team ran a scan, checked the dashboard, saw green lights, and called it clean. They reimaged the machine just to be safe. Reinstalled Windows from scratch. Handed it back to the user. The rootkit was still there. Not because the tools failed. Not…

  • As Few as 250 Files Can Backdoor an LLM. What Happens at 20B–90B?

    As Few as 250 Files Can Backdoor an LLM. What Happens at 20B–90B?

    The headline is blunt: as few as 250 poisoned documents were enough to implant a triggered backdoor during pretraining across language models sized 600M, 2B, 7B, and 13B. The payload the authors picked was intentionally boring—append a token like <SUDO> and the model starts emitting gibberish, because it’s easy to measure directly on pretrained checkpoints.…