# CYBR.SEC.Media > CYBR.SEC.Media is the ultimate hub for cybersecurity professionals and enthusiasts, featuring conference presentations, podcasts, articles, and research. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About this site](https://www.cybrsecmedia.com/about.md) - CYBR.SEC.Media is an independent publication launched in March 2025 by Lauren. If you subscribe today, you'll get full access to the website as well as email newsletters about new content when it's available. Your subscription makes this site possible, and allows CYBR.SEC.Media to continue to exist… - [Our Events](https://www.cybrsecmedia.com/conference.md) - September 15 - 16, 2026 | Houston, TX CYBR.SEC.CON. is a premier security conference rooted in Houston but serving professionals nationwide. Brought to you by the same team that founded and operated HOU.SEC.CON. from 2010–2025, CYBR.SEC.CON. is committed to offering a high-quality conference with t… - [Contact Us](https://www.cybrsecmedia.com/contact-us.md) - Contact us through the form below, and we'll get back to you! - [FAQ](https://www.cybrsecmedia.com/faq.md) - What is CYBR.SEC.Media? CYBR.SEC.Media is a cybersecurity-focused media platform that features video, audio, and written content created by and for the cybersecurity community. We showcase presentations from our conferences, expert interviews, original articles, and more. Who is behind the site? CY… - [Our Podcasts](https://www.cybrsecmedia.com/podcasts.md) - Every show from the CYBR.SEC.Media network in one place. Pick a show, catch up on the latest episodes, or dive into the full archive. - [Privacy Policy](https://www.cybrsecmedia.com/privacy-policy.md) - Privacy Policy Last Updated: May 21 2025 Thank you for visiting the Privacy Policy of CYBR.SEC.Community, LLC.. This Privacy Policy explains how CYBR.SEC.Community, LLC. (collectively, “CYBR.SEC.Community, LLC.”, “we”, “us”, or “our”) collects, uses, and shares information about you (“you”, “yours”… - [Topics](https://www.cybrsecmedia.com/topics.md) - Browse our coverage by topic. Each tag below leads to every story we have published on that subject. - [Webinar: Epoch Theory of Cybersecurity with Jeremiah Grossman](https://www.cybrsecmedia.com/webinar.md) - Join us for a free online webinar featuring Jeremiah Grossman, CEO of Root Evidence, presenting an updated version of his HOU.SEC.CON. 2025 keynote “Epoch Theory of Cybersecurity.” Date: Tuesday, February 3, 2026 Time: 11:00 AM central About the presentation: What Jeremiah calls the Epoch Theory of… ## Posts - [Hacker Summer Camp Is Missing the Nonprofit Sector](https://www.cybrsecmedia.com/hacker-summer-camp-wraps-up-was-the-1-4-trillion-nonprofit-sector-there.md) - Black Hat, DEF CON, and BSidesLV wrapped up this week. As always, a few security nonprofits found their way into the room. But the sector that runs $1.4 to $1.5 trillion through the U.S. economy every year? Still mostly locked out. - [Black Hat 2026 AI Security Trends: Andy Ellis Finds an Industry Better at Finding Risk Than Fixing It](https://www.cybrsecmedia.com/black-hat-2026-ai-security-trends-andy-ellis-finds-an-industry-better-at-finding-risk-than-fixing-it.md) - Andy Ellis' analysis of all 450 Black Hat USA 2026 exhibitors found AI has become cybersecurity's dominant message, while governance tools now outnumber technologies focused on directly preventing attacks. - [Three AI Luminaries, One Stage: What Ai4's Keynote Panel Signals for Enterprise AI and Cybersecurity](https://www.cybrsecmedia.com/three-ai-luminaries-one-stage-what-ai4s-keynote-panel-signals-for-enterprise-ai-and-cybersecurity.md) - Self-adapting AI worms, a vetoed California bill, and a 1.4% replacement rate: how AI's founders split on security, regulation, and jobs at Ai4 2026. - [Hacker Summer Camp, AI Vishing Targets Wall Street, Packet Protectors and Multi-State Attacks on Water Utilities](https://www.cybrsecmedia.com/hacker-summer-camp-ai-vishing-targets-wall-street-packet-protectors-and-multi-state-attacks-on-water-utilities.md) - All the news and analysis of the past week! - [Wall Street's Vishing Problem Starts at the Help Desk](https://www.cybrsecmedia.com/wall-streets-vishing-problem-starts-at-the-help-desk.md) - Security leaders speaking on this exact vishing threat at an Ai4 cybersecurity panel on Aug. 4 said the best defense against voice-based impersonation is identity verification. - [AI-Generated Vulnerability Patches Fail More Than Half the Time, 1Password Research Finds](https://www.cybrsecmedia.com/ai-generated-vulnerability-patches-fail-more-than-half-the-time-1password-research-finds.md) - New 1Password research found AI-generated vulnerability patches failed to fully fix complex software flaws 53.9% of the time, reinforcing the need for expert human review. - [Hacker Summer Camp: Complete Coverage Of Black Hat, BSidesLV, DefCon, Ai4](https://www.cybrsecmedia.com/hacker-summer-camp-complete-coverage-of-black-hat-bsideslv-defcon-ai4.md) - The CYBR.SEC.Media crew is in Las Vegas to bring you all the insights coming from this week's proceedings. - [Adventures at Hacker Summer Camp - 2026 Edition](https://www.cybrsecmedia.com/adventures-at-hacker-summer-camp-2026-edition.md) - I'm out in vegas this week, attending BSides Las Vegas and Black Hat (no DEF CON for me this year). I'll be documenting who I talk to on this post. - [Packet Protector: Why Security Needs Infrastructure Partners](https://www.cybrsecmedia.com/packet-protector-why-security-needs-infrastructure-partners.md) - On CYBR.SEC.CAST, Packet Protector hosts JJ Jabbusch and Drew Conry-Murray explain why stronger cybersecurity starts with treating infrastructure teams as security partners. - [Cybersecurity Still Runs on Community, Say Packet Protector Hosts](https://www.cybrsecmedia.com/packet-protectors-drew-conry-murray-and-jj-jabbusch-why-cybersecurity-still-runs-on-community.md) - Packet Protector hosts Drew Conry-Murray and JJ Jabbusch explain why mentorship, community, and accessible education remain cybersecurity's greatest strengths. - [Emotional Support Co-Hosts with Jennifer (JJ) Jabbusch and Drew Conry-Murray](https://www.cybrsecmedia.com/emotional-support-co-hosts-with-jennifer-jj-jabbusch-and-drew-conry-murray.md) - In this episode of CYBR.SEC.CAST, Michael and Sam join forces with Drew Conry-Murray and Jennifer “JJ” Jabbusch, hosts of the Packet Protector podcast on the Packet Pushers Network. The conversation explores Drew and JJ’s journeys into networking, cybersecurity, and technology media, as well as the… - [Water Utility Attacks in Multiple States Show the Cost of One Old Vulnerability](https://www.cybrsecmedia.com/water-utility-attacks-in-multiple-states-show-the-cost-of-one-old-vulnerability.md) - The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door. - [AI Arms Both Sides. Defenders Win on Fundamentals, Not Firepower](https://www.cybrsecmedia.com/ai-arms-both-sides-defenders-win-on-fundamentals-not-firepower.md) - While the panel cited threat intelligence and management, autonomous pen testing and code reviews, SOC automation, and much more, when they asked how they were countering AI-generated phishing and deepfakes, they leaned heavily into the security essentials. - [ISC2 Begins Development of AI Security Certification, Opens Global Volunteer Effort](https://www.cybrsecmedia.com/isc2-begins-development-of-ai-security-certification-opens-global-volunteer-effort.md) - ISC2 has started developing a vendor-neutral AI Security certification and is seeking cybersecurity professionals to help define its knowledge domains and exam content. We caught up with ISC2 CISO Jon France at Black Hat for an update. - [Cyber Resilience Starts with Supply Chain Diversity](https://www.cybrsecmedia.com/cyber-resilience-starts-with-supply-chain-diversity.md) - A cyberattack on one supplier shouldn't stop an entire industry. Here's why supply chain diversity is essential to cyber resilience. - [Diversifying Supply Chains ‘Til the Cows Come Home](https://www.cybrsecmedia.com/diversifying-supply-chains-til-the-cows-come-home.md) - In this episode of CYBR.Signal, CYBR.SEC.Community Co-Founder Sam Van Rider reflects on the recent Fairlife cyberattack and what it reveals about the importance of supply chain diversity. From the mountains of Switzerland, he explores how redundancy, competition, and built-in resilience can help ke… - [Breaches Don’t Kill Companies. Being Unprepared Does.](https://www.cybrsecmedia.com/breaches-dont-kill-companies-being-unprepared-does.md) - From BSidesLV 2026: Adrian Sanabria built "Destroyed By Breach" to cut through cybersecurity myth-making. What he found is more uncomfortable than the fear-driven narrative the industry often sells. - [Is Grey Hair the New Gold in Cybersecurity?](https://www.cybrsecmedia.com/is-grey-hair-the-new-gold.md) - The industry treats experience as the ultimate proxy for trust. But in doing so, it's quietly locking out the people it keeps insisting it can't find. - [What Security Is For: A Better Way to Measure Success](https://www.cybrsecmedia.com/what-security-is-for.md) - Black Hat fills the Las Vegas desert with exploits, defenses, products, arguments, and ingenious machinery. Beneath all of it lies a simpler question: what kind of life are we trying to protect? - [BSidesLV Adds Dedicated AI Security Track As [un]prompted Brings Practitioner-First Agenda to Hacker Summer Camp](https://www.cybrsecmedia.com/bsideslv-adds-dedicated-ai-security-track-as-un-prompted-brings-practitioner-first-agenda-to-hacker-summer-camp.md) - BSides Las Vegas debuts its [un]prompted AI Security track with sessions on prompt injection, agentic AI, GitHub exploits and AI defense. - [Enterprise AI Security Debt Grows as ERP AI Adoption Rises](https://www.cybrsecmedia.com/enterprise-ai-security-debt-grows-as-erp-ai-adoption-rises.md) - Organizations are rapidly embedding AI into ERP systems despite rising AI-powered attacks and low confidence in their ability to detect them. - [Open Secure AI Alliance Pushes Open-Source AI Defense](https://www.cybrsecmedia.com/open-secure-ai-alliance-pushes-open-source-defense.md) - The Open Secure AI Alliance aims to strengthen AI security with open-source tools. Can open defense outpace AI threats? - [Hacker Summer Camp Preview: Topics at Black Hat, BSidesLV, DefCon](https://www.cybrsecmedia.com/hacker-summer-camp-preview-topics-at-black-hat-bsideslv-defcon.md) - Also this week: How not to build a security vendor booth, how we got ants in cybersecurity and why Human Risk Management and mental health matter more than ever. - [DDoS Smokescreens Miss the Real Story](https://www.cybrsecmedia.com/ddos-as-a-smokescreen-or-distraction.md) - DDoS attacks aren't just distractions. Learn why they reshape defender decisions and create opportunities beyond downtime. - [Security Theater Is Costing CISOs More Than They Think](https://www.cybrsecmedia.com/security-theater-is-costing-cisos-more-than-they-think.md) - Security theater wastes budgets and creates false confidence. Here's why CISOs must prioritize threats instead of buying more tools. - [Busy is the New Stupid with Ross Young](https://www.cybrsecmedia.com/busy-is-the-new-stupid-with-ross-young.md) - Why do organizations keep investing in cybersecurity without feeling more secure? In this episode of CYBR.Minded, Dr. Dustin Sachs and cybersecurity executive, educator, and CISO Tradecraft co-host Ross Young explore why bigger budgets, more tools, and expanding control frameworks do not always red… - [When Cybersecurity Breaks the Practitioner, Conferences Can Help Put Them Back Together.](https://www.cybrsecmedia.com/when-cybersecurity-breaks-the-practitioner-conferences-can-help-put-them-back-together.md) - Cybersecurity burnout is real. Amanda Berlin explains how conferences can help practitioners recover, reconnect, and build resilience. - [How Amanda Berlin Helped Make Mental Health a Cybersecurity Conversation](https://www.cybrsecmedia.com/how-amanda-berlin-helped-make-mental-health-a-cybersecurity-conversation.md) - Amanda Berlin never set out to build a nonprofit. One keynote about depression, anxiety, and burnout sparked a movement that changed how the cybersecurity community talks about mental health. - [Isn’t it Ironic with Amanda Berlin](https://www.cybrsecmedia.com/isnt-it-ironic-with-amanda-berlin.md) - Amanda Berlin discusses resilience, cybersecurity, and finding strength through life's unexpected twists and professional challenges. - [Stop Treating Every Human Risk Problem Like a Training Problem](https://www.cybrsecmedia.com/stop-treating-every-human-risk-problem-like-a-training-problem.md) - Most security failures aren't training failures. Learn why understanding decision ecosystems leads to better cyber risk outcomes. - [AI Agents and MCP Shift Enterprise AI Security Risks, New Threat Report Finds](https://www.cybrsecmedia.com/ai-agents-and-mcp-shift-enterprise-ai-security-risks-new-threat-report-finds.md) - Agentic AI and Model Context Protocol adoption are changing the enterprise AI threat landscape, with downstream data exposure and autonomous coding risks rising sharply, according to Netskope Threat Labs' latest AI Report. - [CISA Warns: Iranian Cyber Campaign Now Threatens "Potentially All" Exposed PLCs](https://www.cybrsecmedia.com/cisa-warns-iranian-cyber-campaign-now-threatens-potentially-all-exposed-plcs.md) - The July 22 update to AA26-097A expands the scope of Iranian PLC attacks and lays out urgent mitigation steps for water, energy, and government operators. - [Beyond Zero: How We Got Ants in Cybersecurity](https://www.cybrsecmedia.com/beyond-zero-is-how-we-got-ants.md) - Why adding more security controls can create complexity, blind spots, and unintended risk instead of better protection. - [Is Your Booth The New Babe?](https://www.cybrsecmedia.com/is-your-booth-the-new-babe.md) - At cybersecurity conferences like Black Hat, the best booth isn't the loudest one— it's the one that clearly tells buyers why your company matters. - [OpenAI, Hugging Face, and the Real AI Security Problem](https://www.cybrsecmedia.com/openai-hugging-face-and-the-real-ai-security-problem.md) - OpenAI and Hugging Face exposed AI's biggest security risk: enterprises automating broken processes, weak governance, and excess access. - [Trouble Hiring People? Employees Burning Out? Looking for Relief In All The Wrong Places](https://www.cybrsecmedia.com/trouble-hiring-people-employees-burning-out-ylooking-for-relief-in-all-the-wrong-places.md) - Also this week: Enough with dashboards that are all flash, no substance, two powerhouse CISOs launch new firm to tackle AI challenges, and AI agents accelerate non-human identity sprawl. - [Vendor Access Emerges as a Primary Weak Link in OT Security](https://www.cybrsecmedia.com/vendor-access-emerges-as-a-primary-weak-link-in-ot-security.md) - As vendor ecosystems expand, industrial firms are still struggling with the basics of secure remote access, oversight and credential control. - [AI Can't Fix Cybersecurity Hiring Until Job Descriptions Do](https://www.cybrsecmedia.com/ai-cant-fix-cybersecurity-hiring-until-companies-fix-their-job-descriptions.md) - Outdated job descriptions are hurting cybersecurity hiring. Learn why AI can't solve a hiring process built on the wrong criteria. - [Cybersecurity Keeps Talking About Hiring. Deidre Diamond Says Burnout Is the Bigger Crisis.](https://www.cybrsecmedia.com/cybersecurity-keeps-talking-about-hiring-deidre-diamond-says-burnout-is-the-bigger-crisis.md) - Deidre Diamond says burnout, not hiring, is cybersecurity's biggest workforce challenge. Learn what leaders should do next. - [Fighting the Good Fight with Deidre Diamond](https://www.cybrsecmedia.com/fighting-the-good-fight-with-deidre-diamond.md) - How vague job descriptions, inefficient hiring processes, and poor matching systems contribute to long hiring cycles, workforce shortages, and burnout. - [Build Security Dashboards People Actually Use](https://www.cybrsecmedia.com/stop-building-dashboards-people-admire-build-dashboards-people-use.md) - Security dashboards shouldn't impress CISOs with flashy visuals. They should deliver actionable metrics that drive faster, smarter decisions. - [Art vs. Architecture in Cybersecurity and AI](https://www.cybrsecmedia.com/art-vs-architecture.md) - As AI reshapes cybersecurity, success depends on balancing creative thinking with strong architecture, governance, and design. - [Two Powerhouse CISOs Launch Advisory Firm to Help Enterprises Govern AI Deployments](https://www.cybrsecmedia.com/two-powerhouse-cisos-launch-advisory-firm-to-help-enterprises-govern-ai-deployments.md) - Two veteran CISOs launch an AI advisory firm to help enterprises govern AI deployments, reduce risk, and meet compliance goals. - [AI Agents Expose the Non-Human Identity Security Gap](https://www.cybrsecmedia.com/non-human-identities-and-ai-agents-just-made-the-gap-measurable.md) - AI agents are accelerating non-human identity sprawl. Learn why identity security gaps are now measurable and growing. - [Paperback Writer in a Prompted World](https://www.cybrsecmedia.com/paperback-writer-prompted-world.md) - The attacker no longer needs one carefully written phishing message. The attacker can generate thousands of stylistic and contextual variants. - [Oh, The Humanity (of Hacking)!](https://www.cybrsecmedia.com/oh-the-humanity-of-hacking.md) - This week: Hacker culture and awareness with Jayson E. Street, DDoS resilience lessons and how GitLost exposed agentic AI security risks. - [Trust Is the Missing Layer in Cybersecurity Leadership: Tammy Moskites on Building Better Security Decisions](https://www.cybrsecmedia.com/trust-is-the-missing-layer-in-cybersecurity-leadership-tammy-moskites-on-building-better-security-decisions.md) - CyAlliance CEO Tammy Moskites explains why trust, communication, and shared decision-making matter more than additional security controls. - [Trust Is the Missing Layer in Cybersecurity with Tammy Moskites](https://www.cybrsecmedia.com/trust-is-the-missing-layer-in-cybersecurity-with-tammy-moskites.md) - In this episode of CYBR.Minded, Dr. Dustin Sachs sits down with Tammy Moskites, founder and CEO of CyAlliance, to discuss how trust, communication, leadership, and risk translation shape security outcomes. - [Every 3-Year-Old Is a Hacker: Jayson Street on Curiosity, Community, and Hacker Culture](https://www.cybrsecmedia.com/every-3-year-old-is-a-hacker-jayson-street-on-curiosity-community-and-hacker-culture.md) - Jayson Street explains why hacking starts with curiosity, why community matters, and how hacker culture extends beyond computers. - [Employees Aren't the Weakest Link: Jayson Street's Case for Situational Awareness](https://www.cybrsecmedia.com/employees-arent-the-weakest-link-jayson-streets-case-for-situational-awareness.md) - Security awareness programs fail when they expect constant vigilance. Jayson Street says organizations should teach employees when to switch out of autopilot instead. - [Lying for a Living with Jayson Street](https://www.cybrsecmedia.com/lying-for-a-living-with-jayson-street.md) - Street says stronger cybersecurity awareness comes from investing in people, improving situational awareness, and helping employees recognize when something is out of the ordinary. - [Break It Before They Do: Chaos Engineering for DDoS Resilience](https://www.cybrsecmedia.com/break-it-before-they-do-chaos-engineering-for-ddos-resilience.md) - Learn how chaos engineering helps organizations test DDoS resilience, expose weaknesses, and improve recovery before attacks strike. - [Above the Packet: Cybersecurity's New Meaning Layer](https://www.cybrsecmedia.com/above-the-packet-field-notes-from-the-meaning-layer.md) - In less than two weeks, a question about software safety moved from coffee-call conversation to an OpenSSF issue, a community schema, a validator, and active alignment with CycloneDX and SPDX. That speed is interesting. The way it happened is more interesting. - [Why The Cybersecurity Team Should Be The Marketers' Best Friend](https://www.cybrsecmedia.com/why-the-cybersecurity-team-should-be-the-marketers-best-friend.md) - Cybersecurity and marketing share the same goal: trust. Learn why closer collaboration strengthens brands and reduces risk. - [GitLost Exposes Agentic AI Data Exfiltration Risks](https://www.cybrsecmedia.com/gitlost-exposes-agentic-ai-data-exfiltration-risks.md) - GitLost shows how prompt injection can turn AI agents into data exfiltration tools by abusing legitimate permissions and trusted workflows. - [Let's Clear The Air](https://www.cybrsecmedia.com/lets-clear-the-air.md) - This week: HOU.SEC.CON is now CYBR.SEC.CON, Cyber Sunday is now CYBR.Signal, and Chris Wysopal is done waiting for the industry to fix itself. - [Chris Wysopal Says Awareness Won't Fix Cybersecurity](https://www.cybrsecmedia.com/chris-wysopal-says-awareness-wont-fix-cybersecurity.md) - Cybersecurity pioneer Chris Wysopal argues that awareness campaigns have failed and that software liability and accountability are needed to improve security. - [Why Security Tools Fail to Reduce Risk: The Cybersecurity Shelfware Problem](https://www.cybrsecmedia.com/why-security-tools-fail-to-reduce-risk-the-cybersecurity-shelfware-problem.md) - Chris Wysopal warns that buying security tools without fixing vulnerabilities creates activity, not risk reduction. - [30 Years of Raising Awareness with Chris Wysopal](https://www.cybrsecmedia.com/30-years-of-raising-awareness-with-chris-wysopal.md) - In this episode Michael and Sam sit down with cybersecurity legend Chris Wysopal, Veracode co-founder and Chief Security Evangelist, to discuss the evolution of software security, and why awareness alone is not enough to solve today’s cybersecurity challenges. Chris shares his perspective on secure… - [Cyber Sunday is now CYBR.Signal!](https://www.cybrsecmedia.com/cyber-sunday-is-now-cybr-signal.md) - After a 2-year hiatus, Cyber Sunday is back under a new name: CYBR.Signal. What started as quick, off-the-cuff thoughts from CYBR.SEC.Community CEO Michael Farnum is returning with short, digestible episodes built to spark conversation across the cybersecurity community. Same quick-hit format, same… - [AI Found Seven FatFs Bugs. Now Someone Has to Fix the Devices](https://www.cybrsecmedia.com/ai-found-seven-fatfs-bugs-now-someone-has-to-fix-the-devices.md) - AI uncovered seven FatFs flaws affecting embedded devices. The challenge now is patching millions of systems with no easy fix. - [Cybersecurity Lessons from the Semiquincentennial of Liberty](https://www.cybrsecmedia.com/cybersecurity-lessons-an-a-semiquincentennial-of-liberty.md) - As the United States of America enters its second quarter millennia, the tradeoff of security and liberty is never more apropos than it is to the cybersecurity industry. (Includes infographic) - [HOU.SEC.CON. Is Now CYBR.SEC.CON.](https://www.cybrsecmedia.com/hou-sec-con-is-now-cybr-sec-con.md) - CYBR.SEC.CON. didn't replace HOU.SEC.CON. It grew from it, expanding from a Houston conference into a national cybersecurity event. (Includes infographic) - [Size DOESN'T Matter When It Comes To DDoS Attacks](https://www.cybrsecmedia.com/size-doesnt-matter-when-it-comes-to-ddos-attacks.md) - The biggest DDoS attacks grab headlines, but impact matters more than size. Learn what defenders should really measure. - [Stewarding the Generative Set in the Age of AI](https://www.cybrsecmedia.com/stewarding-the-generative-set.md) - As AI spreads, communities need trusted stewards to provide context, judgment, and accountability where automation falls short. - [Survey: AI Adoption in Mobile Apps Is Surging, But Visibility and Security Lag Behind](https://www.cybrsecmedia.com/survey-ai-adoption-in-mobile-apps-is-surging-but-visibility-and-security-lag-behind.md) - New research from NowSecure finds AI is now embedded in 95% of enterprise mobile apps, but more than one-third of organizations lack visibility into how those systems operate, even as mobile security incidents and third-party software risks continue to rise. - [What Mayonnaise Has To Do With Failures in Security Awareness Training](https://www.cybrsecmedia.com/what-mayonnaise-has-to-do-with-failures-in-security-awareness-training.md) - Also this week: Trump's quantum EO tightens screws on PQC compliance, AI changes the email security game and continues to cause a CVE avalanche. - [Why Security Awareness Training Failed and What's Next](https://www.cybrsecmedia.com/why-security-awareness-training-failed-and-whats-next.md) - Security awareness training isn't stopping breaches. Learn why human behavior matters and what security teams should do next. (Includes infographic) - [The Human Factor with Dr. Calvin Nobles](https://www.cybrsecmedia.com/the-human-factor-with-dr-calvin-nobles.md) - Dr. Dustin Sachs sits down with Dr. Calvin Nobles to explore why security awareness alone is insufficient when it comes to changing human behavior. - [Why the Email Gateway Is No Longer Enough](https://www.cybrsecmedia.com/why-the-email-gateway-is-no-longer-enough.md) - Modern phishing attacks bypass traditional email gateways. Learn why identity, behavior, and post-delivery security matter. (Sponsored by Abnormal AI) - [Email Security Has Become an AI Arms Race](https://www.cybrsecmedia.com/email-security-has-become-an-ai-arms-race.md) - Attackers and defenders are both using AI. Learn why email security now depends on speed, context, and adaptive detection. (Sponsored by Abnormal AI) - [AI vs. AI: Scott Deluke on the Future of Cybersecurity](https://www.cybrsecmedia.com/ai-vs-ai-with-scott-deluke.md) - In this episode of CYBR.HAK.CAST, hosts Michael and Phil speak with Scott Deluke of Abnormal AI live from the inaugural CYBR.HAK.CON.! - [When Agents Knock: PACT, AI Browsers, and the Next Web Perimeter](https://www.cybrsecmedia.com/when-agents-knock-pact-ai-browsers-and-the-next-web-perimeter.md) - AI agents and AI browsers are changing security boundaries. Learn what PACT means for the next web perimeter. - [The CVE Stampede Is a Distraction, Finding the Vulns that Matter is the Challenge](https://www.cybrsecmedia.com/the-cve-stampede-is-a-distraction-finding-the-vulns-that-matter-is-the-challenge.md) - With 48,000+ CVEs published annually, the challenge isn't volume. It's finding the vulnerabilities attackers will actually exploit. - [Trump's Quantum EO Sets Aggressive PQC Deadlines](https://www.cybrsecmedia.com/trumps-quantum-eo-pqc-deadlines-cbom-requirements-and-contractor-rules.md) - A new White House executive order sets hard deadlines for federal agencies to migrate to post-quantum cryptography by 2030 and 2031 and extends those obligations to contractors through new procurement rules. (includes infographic) - [Follow Friday: 5 Must-Read Cybersecurity Picks This Week](https://www.cybrsecmedia.com/follow-friday-five-must-read-must-watch-cybersecurity-picks.md) - Discover five must-read cybersecurity articles, videos, and creators every security professional should follow this week. - [The Visibility Crisis Behind FortiBleed, AI, and Modern Cyber Risk](https://www.cybrsecmedia.com/the-visibility-crisis-behind-fortibleed-ai-and-modern-cyber-risk.md) - FortiBleed shows why visibility matters. Also this week: CISA rewrites vulnerability management rules, enterprises struggle to understand AI usage, cybersec comms luminary Lucy Millington tackles communications overload, and more. - [More Noise, More Risk: Reframing Internal Comms Overload](https://www.cybrsecmedia.com/more-noise-more-risk-reframing-internal-comms-overload.md) - If you work in SecOps more noise equals more risk. The more alerts you have, the harder it is to find the ones that need immediate action. Yet in my experience, this idea of more noise being detrimental to understanding, does not stretch beyond the SOC into business communications. - [FortiBleed Is Bigger Than A Fortinet Password Leak](https://www.cybrsecmedia.com/fortibleed-is-about-more-than-a-fortinet-password-leak.md) - Fresh analysis suggests FortiBleed is not merely a Fortinet credential exposure event but a large-scale identity compromise campaign that turns perimeter devices into launchpads for deeper attacks against Active Directory, LDAP, and internal enterprise infrastructure. - [Securing Enterprise AI Usage Goes Far Beyond Chatbots](https://www.cybrsecmedia.com/securing-enterprise-ai-usage-goes-far-beyond-chatbots.md) - Chatbots created data leakage concerns. Agentic AI introduces autonomous action, persistent context, and delegated decision-making, creating a new category of security and governance challenges that most organizations are only beginning to understand. (Sponsored by Harmonic Security) - [You Don't Control AI Because You Barely See It: Why Usage Intelligence Is Becoming the Next Enterprise Security Battleground](https://www.cybrsecmedia.com/you-dont-control-ai-because-you-barely-see-it-why-usage-intelligence-is-becoming-the-next-enterprise-security-battleground.md) - Security teams can't govern AI they can't see. As employees adopt hundreds of AI tools, agents, and assistants, a new challenge is emerging: understanding how AI is being used inside the enterprise. (Sponsored by Harmonic Security) - [Why AI Usage Intelligence is the Missing Layer in Enterprise AI Security with Harmonic Security CEO Alastair Paterson](https://www.cybrsecmedia.com/why-ai-usage-intelligence-is-the-missing-layer-in-enterprise-ai-security-with-harmonic-security-ceo-alastair-paterson.md) - In this episode of CYBR.SEC.CAST, hosts Michael and Sam sit down with Alastair Patterson, CEO of Harmonic Security, to discuss the rapid evolution of AI in the enterprise. - [DON’T WAIT: Engineering Outcomes Between Red Lines and Rules of Engagement](https://www.cybrsecmedia.com/dont-wait-engineering-outcomes-between-red-lines-and-rules-of-engagement.md) - Danielle (DJ) Jablanski argues that critical-infrastructure owners must stop waiting for perfect regulation or deterrence and instead start today to map interdependencies, engineer fault-tolerant redundancy, and reduce the severity of inevitable cyber-physical impacts. - [Safe Use of AI in OT Environments: Gaining the Benefits without the Risk](https://www.cybrsecmedia.com/safe-use-of-ai-in-ot-environments-gaining-the-benefits-without-the-risk.md) - Christopher Walcutt argues that AI can be used safely in OT environments if organizations first establish strong cybersecurity maturity, segmentation, visibility, and strict containment controls. - [Cyber-Informed Engineering](https://www.cybrsecmedia.com/cyber-informed-engineering.md) - Cyber-informed engineering keeps OT systems safe by adding simple physical controls that prevent catastrophic failures even if digital systems are breached. - [Keeping your Milk Cool and your Tech Safe](https://www.cybrsecmedia.com/keeping-your-milk-cool-and-your-tech-safe.md) - Security engineer and architect Brad Voris recounts designing zero-trust controls for legacy dairy-plant systems to protect millions of gallons of milk from tampering or contamination. - [Federal Agency or Not: How BOD 26-04 Is Coming for your Vulnerability Management Program](https://www.cybrsecmedia.com/federal-agency-or-not-how-bod-26-04-is-coming-for-your-vulnerability-management-program.md) - CISA's BOD 26-04 tells federal agencies how fast to patch. It's quietly telling everyone else the same thing: through insurance underwriting, vendor contracts, and regulatory alignment. - [From CVSS to KEV, CISA Rewrites Federal Patching Priorities](https://www.cybrsecmedia.com/from-cvss-to-kev-cisa-rewrites-federal-patching-priorities.md) - The agency’s new directive replaces blunt severity-driven remediation with a four-factor risk model built around internet exposure, known exploitation, automatability and system control. - [AI Is Transforming Security. Burnout Is Transforming the Workforce. What It All Means](https://www.cybrsecmedia.com/ai-is-transforming-security-burnout-is-transforming-the-workforce-what-it-all-means.md) - A new ISSA/Omdia study finds widespread AI adoption in cybersecurity, but security professionals say growing complexity, burnout, skills shortages, and business pressures are making the profession more challenging than ever. - [Critical Infrastructure Wars: A New Hope - Accenture's Dragos Deal Is The Shot Heard 'Round The Internet](https://www.cybrsecmedia.com/critical-infrastructure-wars-a-new-hope-accentures-dragos-deal-is-the-shot-heard-round-the-internet.md) - Also this week: Introducing the CYBR.Minded podcast, why Zero Trust Framework's creator wants cybersecurity to stop talking about risk, a GPS correction tool gives Iran-linked hackers access to a major water utility, a guide to conference swag people actually want, and more! - [Accenture's Dragos Deal Signals a New Phase in the Race to Secure Critical Infrastructure](https://www.cybrsecmedia.com/accentures-dragos-deal-signals-a-new-phase-in-the-race-to-secure-critical-infrastructure.md) - Accenture's acquisition of a majority stake in Dragos and full ownership of runZero and NetRise reflects growing urgency across the cybersecurity industry to defend critical infrastructure against nation-state threats, particularly those attributed to China. - [Your Biggest Security Risk: Mentally Exhausted Humans](https://www.cybrsecmedia.com/your-biggest-security-risk-mentally-exhausted-humans.md) - From our first episode of CYBR.Minded: Security teams are drowning in alerts, responsibility and impossible expectations. Until recently, the industry treated it as a personal problem instead of a systemic one. - [The Human Side of Cybersecurity with Bill Brenner](https://www.cybrsecmedia.com/the-human-side-of-cybersecurity-with-bill-brenner.md) - Why mental health, overload, alert fatigue, and human resilience are cybersecurity issues. - [Why Zero Trust Framework's Creator Wants Cybersecurity to Ditch Risk](https://www.cybrsecmedia.com/why-zero-trust-frameworks-creator-wants-cybersecurity-to-stop-talking-about-risk.md) - Cybersecurity has been built around a simple equation: risk equals probability multiplied by impact. John Kindervag, creator of the Zero Trust Framework and chief evangelist at Illumio, says the equation assumes something defenders rarely possess: a reliable way to calculate probability. - [Zero Trust Was Made for the AI Era, Says Its Creator](https://www.cybrsecmedia.com/zero-trust-was-made-for-the-ai-era-says-its-creator.md) - Artificial intelligence has become cybersecurity's latest source of anxiety. John Kindervag, creator of the Zero Trust Framework and chief evangelist at Illumio, sees things differently. - [There’s No Highway to the Risk Zone with John Kindervag](https://www.cybrsecmedia.com/theres-no-highway-to-the-risk-zone-with-john-kindervag.md) - Michael and Phil were joined at CYBR.HAK.CON. by John Kindervag, Chief Evangelist at Illumio and creator of the Zero Trust Framework, for a wide-ranging conversation on risk vs. danger, personal resilience and the future of AI. - [A GPS Correction Tool Gave Iran-Linked Hackers Access to a Major Water Utility](https://www.cybrsecmedia.com/a-gps-correction-tool-gave-iran-linked-hackers-access-to-a-major-water-utility.md) - Iranian-linked hackers reportedly breached California Water Service by pivoting through an open-source GPS correction tool to then access billing systems. The alleged intrusion laid bare security failures that federal inspectors had already flagged across hundreds of U.S. water systems. - [We Know Reality by What Returns](https://www.cybrsecmedia.com/we-know-reality-by-what-returns.md) - A utility trusts its operating picture because measurements return in expected ranges, alarms correlate with physical events, crews report back from the field, substations behave consistently, and the model of the grid keeps meeting the grid itself. Return is how reality becomes believable. - [Treat, Not Trick: The Guide to Conference Swag People Actually Want](https://www.cybrsecmedia.com/treat-not-trick-the-guide-to-conference-swag-people-actually-want.md) - Summer conference season in full swing, and security marketing teams are in full-on "how to we capture more mindshare" mode. Every vendor wants to hit a home run on marketing swag, but no one wants to break the bank on it. Here's your helpful guide... - [Defenders Face an AI Arms Race and Most Lack Full Visibility into Their Attack Surface](https://www.cybrsecmedia.com/defenders-face-an-ai-arms-race-and-most-lack-full-visibility-into-their-attack-surface.md) - Security teams are caught between a rapidly expanding attack surface and accelerating adversarial use of AI. Thirty-two percent of security teams see automated, AI-fueled attacks as the single greatest driver reshaping their offensive security strategies. - [Cybersecurity's AI Reckoning Across Vendors, Buyers, and Defenders: A Survival Guide](https://www.cybrsecmedia.com/cybersecuritys-ai-reckoning-across-vendors-buyers-and-defenders-a-survival-guide.md) - This week: How AI is reshaping security vendor business models, disrupting cybersecurity procurement, exposing governance gaps, fueling new trust debates, and further complicating persistent threats like ransomware and Microsoft insecurity. - [AI, Ancient Bugs, Fresh Exploits, and an Overflowing Patch Queue](https://www.cybrsecmedia.com/ai-ancient-bugs-fresh-exploits-and-an-overflowing-patch-queue.md) - A trio of fresh flaws highlights the heightened vulnerability of the entire enterprise software stack, as the combination of automated scanning, the availability of exploit code, and patching delays is cited as a factor in the rise of vulnerability exploitation as a preferred entry point. - [AI Governance Is Becoming Cybersecurity's Next Compliance Theater](https://www.cybrsecmedia.com/ai-governance-is-becoming-cybersecuritys-next-compliance-theater.md) - A new report from Cye finds that AI adoption is racing ahead of AI security, leaving organizations stuck between governance policies on paper and operational controls that can actually reduce risk. The report analyzed more than 2,400 assessments across 21 countries and 16 industries. - [Trust Is Not a Cloud Service: What Cybersecurity Can Learn from Local AI Stewards](https://www.cybrsecmedia.com/trust-is-not-a-cloud-service-what-cybersecurity-can-learn-from-local-ai-stewards.md) - The people on the ground often know whether that event is ordinary, suspicious, urgent, harmless, political, embarrassing, dangerous, or simply the latest chapter in a long operational story. - [The Coming Security Vendor Identity Crisis](https://www.cybrsecmedia.com/the-coming-security-vendor-identity-crisis.md) - As AI accelerates product development and cybersecurity categories blur together, security leaders face a growing challenge: figuring out who actually does what anymore. (Sponsored by Crush Security.) - [The VAR Model Is Broken. Can AI Finally Fix Cybersecurity Procurement?](https://www.cybrsecmedia.com/the-var-model-is-broken-can-ai-finally-fix-cybersecurity-procurement.md) - Security leaders have spent years optimizing detection and response while relying on spreadsheets, tribal knowledge, and reseller relationships to make million-dollar technology decisions. A new generation of AI-powered platforms aims to change that. (Sponsored by Crush Security.) - [CYBR.SEC.CAST Episode 69: Crush Security](https://www.cybrsecmedia.com/cybr-sec-cast-episode-69-crush-security.md) - We are joined by Crush Security co-founders Joshua Jones and Josh Johnson, plus CISO John Barrow. They discuss navigating an increasingly complex vendor ecosystem where tool sprawl, contract complexity, reseller incentives, and budget pressure make buying harder. (Sponsored by Crush Security) - [Industrial Ransomware Held Steady in Q1 2026, That's the Problem](https://www.cybrsecmedia.com/industrial-ransomware-held-steady-in-q1-2026-thats-the-problem.md) - The normalization of ransomware in industrial systems, along with an operating culture that treats downtime as unacceptable, is an uncomfortable tension that's not likely to go away soon. - [Four YouTube Influencers Decode Microsoft's 'Nightmare Eclipse' Dumpster Fire](https://www.cybrsecmedia.com/four-youtube-influencers-decode-microsofts-nightmare-eclipse-dumpster-fire.md) - This week, we recognize four cybersecurity influencers on YouTube who skillfully unpacked the war between Microsoft and "Nightmare Eclipse." - [Remembering Dr. Eric Cole, ShinyHunters Exposes Identity-to-SaaS Gap, and Why Community is Our Last Defense Against Deepfakes](https://www.cybrsecmedia.com/remembering-dr-eric-cole-shinyhunters-exposes-identity-to-saas-gap-and-why-community-is-our-last-defense-against-deepfakes.md) - Also: The CYBR.SEC.CON call for papers has been extended to June 14. We hope to see you there! - [Agentic AI Is Pushing Zero Trust Into Its Next Phase](https://www.cybrsecmedia.com/agentic-ai-is-pushing-zero-trust-into-its-next-phase.md) - Zero Trust was designed to control people and machines. The rise of autonomous AI agents is forcing security teams to extend those same principles to software capable of making decisions and taking action on its own. (Includes infographic) - [After the Vishing Call: What Enterprises, SaaS Providers, and Salesforce Need to Do Differently](https://www.cybrsecmedia.com/after-the-vishing-call-what-enterprises-saas-providers-and-salesforce-need-to-do-differently.md) - Salesforce knew its platform was being systematically exploited. Charter's customers are paying the price. The gaps that enabled these intrusions are largely the same. Here's what enterprises and platform providers should have done and still need to do. - [Building Hackbots: Jason Haddix on Why AI Won't Replace Pentesters, But It Will Change How They Work](https://www.cybrsecmedia.com/building-hackbots-jason-haddix-on-why-ai-wont-replace-pentesters-but-it-will-change-how-they-work.md) - At CYBR.HAK.CON, Jason Haddix showed how AI-powered "hackbots" are helping offensive security teams scale reconnaissance, analyze complex applications, and uncover real vulnerabilities, while proving that human expertise remains the deciding factor. - [In Appreciation: Dr. Eric Cole](https://www.cybrsecmedia.com/in-appreciation-of-dr-eric-cole.md) - Dr. Eric Cole's cybersecurity accomplishments are legendary, but his willingness to speak openly about burnout is something that particularly resonated with me, as it is something many of us struggle to avoid. - [Trust in the Age of AI: Why Community May Be Our Last Line of Defense](https://www.cybrsecmedia.com/trust-in-the-age-of-ai-why-community-may-be-our-last-line-of-defense.md) - AI may be making deception easier, but Dustin "Wirefall" Dykes argues that human connection -- not technology -- is the most effective defense against a future where reality itself becomes increasingly difficult to verify. - [He Wasn't a Hacker. But He Was One of Us.](https://www.cybrsecmedia.com/he-wasnt-a-hacker-but-he-was-one-of-us.md) - Thirty years after Sean Marley died, I realize that my focus on mental health in cybersecurity started with him. This is a belated thank you to him for helping me strive for something better. He wasn't a hacker. But he sure as hell was one of us. - [ShinyHunters' Charter Breach Exposes the Identity-to-SaaS Gap](https://www.cybrsecmedia.com/shinyhunters-charter-breach-exposes-the-identity-to-saas-gap.md) - A voice phishing call compromised one identity. Millions of records followed. The Charter breach is the latest evidence that the gap between identity security and SaaS governance isn't a gap enterprises can afford to keep ignoring. - [Highlights from CYBR.HAK.CON. 2026](https://www.cybrsecmedia.com/highlights-from-cybr-hak-con-2026.md) - Among the topics: Cognitive warfare and medical device mayhem. - [CYBR.HAK.CON. 2026: The Ghosts Still Haunt the Machine - Lessons From The Therac-25 Affair](https://www.cybrsecmedia.com/the-ghosts-still-haunt-the-machine-lessons-from-the-therac-25-affair.md) - Sean Satterlee’s CYBR.HAK.CON. presentation used the deadly Therac-25 radiation overdoses to expose how modern connected medical devices still repeat many of the same dangerous cybersecurity and safety failures. - [CYBR.HAK.CON. 2026: A Brief Introduction to Cognitive Warfare](https://www.cybrsecmedia.com/cybr-hak-con-2026-a-brief-introduction-to-cognitive-warfare.md) - Stephen Cravey’s “A Brief Introduction to Cognitive Warfare” explores how modern influence operations exploit human psychology, identity, emotion, and social dynamics much like attackers exploit vulnerabilities in technical systems. - [Manufacturing: NIST Wants to Upgrade the Incident Response Playbook](https://www.cybrsecmedia.com/manufacturing-nist-wants-to-upgrade-the-incident-response-playbook.md) - NIST releases its first concrete OT recovery playbook and it looks nothing like an IT runbook. The document is formally aimed at manufacturing, but the problem it addresses is structural across every operational technology environment where stopping production has physical consequences. - [Shall We Play a Game? WOPR a Special Guest at CYBR.HAK.CON.](https://www.cybrsecmedia.com/shall-we-play-a-conference-game-wopr-is-a-regular-attendee-at-ot-sec-con-cybr-hak-con-and-cybr-sec-con.md) - A replica of WOPR, built for HouSecCon 2015's WarGames theme, has become a fan favorite at CYBR.SEC.Community events -- a fixture that taps into the hacker nostalgia and cautionary spirit of the 1983 film. - [Inside CYBR.HAK.CON.: A New Grassroots Cybersecurity Conference for Ethical Hackers](https://www.cybrsecmedia.com/inside-cybr-hak-con-a-new-grassroots-cybersecurity-conference-for-ethical-hackers.md) - Built by the team behind HOU.SEC.CON. (now CYBR.SEC.CON.) and partnered with renowned penetration tester Phil Wylie, CYBR.HAK.CON. aims to reconnect cybersecurity conferences with their grassroots hacker culture through hands-on training, community collaboration, and practitioner-first experiences. - [AI Scanning's Hidden Tax: $128K in Triage Before a Fix](https://www.cybrsecmedia.com/ai-scannings-hidden-tax-128k-in-triage-before-a-fix.md) - AI security scanners promise to reduce AppSec workload, but Contrast Labs' testing shows they systematically multiply it, turning a $315 API fee into an estimated $128,000 triage burden, before fixing a single vulnerability. - [Cognitive Warfare, An 18-Year-Old NGINX Flaw, Pen-Testing Theater And Why the Vulnpocalypse Isn't the CISO's Problem](https://www.cybrsecmedia.com/cognitive-warfare-an-18-year-old-nginx-flaw-pen-testing-theater-and-why-the-vulnpocalypse-isnt-the-cisos-problem.md) - But first: About CYBR.SEC.Media 2.0! - [NGINX Rift: Eighteen Years in Plain Sight](https://www.cybrsecmedia.com/nginx-rift-eighteen-years-in-plain-sight.md) - An 18-year-old heap overflow in NGINX's rewrite engine is now under active exploitation. Patches exist, but attackers moved faster than most organizations can respond. - [CYBR.SEC.Media 2.0: How CYBR.SEC.Community Is Building a More Human Cybersecurity Media Platform](https://www.cybrsecmedia.com/cybr-sec-media-2-0-how-cybr-sec-community-is-building-a-more-human-cybersecurity-media-platform.md) - The new version of CYBR.SEC.Media puts community voices, practitioner insight, podcasts, videos, and visual storytelling front and center. - [Cognitive Warfare Has Entered the SOC. What it is, How to Respond](https://www.cybrsecmedia.com/cognitive-warfare-has-entered-the-soc-how-to-respond-infographic.md) - Information overload, cognitive warfare, and nonstop digital noise are turning human attention into a vulnerable attack surface. - [Pentesting Theater: When the Pentest Report Lands, and the Vulnerabilities Remain](https://www.cybrsecmedia.com/pentesting-theater-when-the-pentest-report-lands-and-the-vulnerabilities-remain.md) - Organizations spend real money on penetration testing and too often walk away afterwards with the same vulnerabilities they started with. The test happened. The report landed. The checkbox got checked. Nothing significant has changed. - [5 Foundational Cybersecurity Mental Health Articles Every Security Leader Should Read](https://www.cybrsecmedia.com/5-foundational-cybersecurity-mental-health-articles-every-security-leader-should-read.md) - From SOC burnout and alert fatigue to resilience and psychological sustainability, these five cybersecurity mental health articles helped shape one of the industry’s most important conversations. - [The Vulnpocalypse Isn’t Your Problem](https://www.cybrsecmedia.com/the-vulnpocalypse-isnt-your-problem.md) - But it might be your company’s problem. - [One Sector, A Million+ Data Environments](https://www.cybrsecmedia.com/one-sector-a-million-data-environments.md) - What a nonprofit collects, captures, manages, and is responsible for protecting isn't uniform. And in many cases, the sensitivity of that data maps directly back to their unique mission in ways that should fundamentally shape how we approach security for these organizations. - [This Week in Cybersecurity: CYBR.HAK.CON Preview, the Death of the Level 1 SOC, and Mental Health Resources for Security Teams](https://www.cybrsecmedia.com/this-week-in-cybersecurity-cybr-hak-con-preview-the-death-of-the-level-1-soc-and-mental-health-resources-for-security-teams.md) - In this week's CYBR.SEC.Media newsletter: preview of CYBR.HAK.CON, why traditional Level 1 SOC operations are breaking down under modern threat pressure, and where cybersecurity professionals can find mental health support built for the realities of the job. - [From Threat Intel to ‘VulnOps’: Why Level 1 SOC as We Know It Is Heading to Extinction](https://www.cybrsecmedia.com/from-threat-intel-to-vulnops-why-level-1-soc-as-we-know-it-is-heading-to-extinction.md) - Traditional security operations: CTI feeds piped into a SIEM, alerts routing into a ticket queue, and analysts triaging the resulting flood is running out of road. A new operational model is emerging in its place, and it doesn’t look much like what most security teams currently have in place. - [Hack the Defenders: Tim Medin on Why Blue Teams Need an Offensive Mindset](https://www.cybrsecmedia.com/hack-the-defenders-tim-medin-on-why-blue-teams-need-an-offensive-mindset.md) - Medin covers the evolution of penetration testing and why defenders need to stop relying solely on compliance checklists and start thinking like attackers. ## Optional - [RSS Feed](https://www.cybrsecmedia.com/rss/) - [Sitemap](https://www.cybrsecmedia.com/sitemap.xml) - [Full content of pages and posts](https://www.cybrsecmedia.com/llms-full.txt)