Breach of Confidence — 12 June 2026

This week I think I’d like a refund on my optimism. The Doxxer Gets Doxxed Someone in Spain leaked the personal details of police, prosecutors, and cyber officials across multiple platforms. They got arrested in Granada last week. The poetic justice of doxxing the very people tasked with preventing doxxing is absolutely chef’s kiss. Read more in the Breach of Confidence — 12 June 2026 article.

Mythos 5 Restricted by US Government for Being Too Dangerous

For those of you who have been questioning the power and impact of Mythos, claiming the initial restricted use (Project Glasswing) was just a marketing ploy, I urge you to reconsider and listen to cybersecurity experts.

The Mythos Effect is real. It is a signal of change across the industry, forced by the order-of-magnitude performance in finding and exploiting vulnerabilities by a new generation of AI models (soon from several vendors).

Anthropic is acting ethically, but unfortunately, such performance gains cannot be contained for long. Every major AI vendor is pursuing this level of competency, which impacts security capabilities to respond and close weaknesses before they are exploited. Here are some articles to come up to speed:

Saturday Security: CISA’s New 72-Hour Patch Rule

For years the mantra in IT security has been simple — patch everything. But in the age of AI that’s no longer realistic. And this week CISA made it official with a new approach that changes the game for federal agencies and sets a precedent for the entire industry.

BSides Seattle 2026 – Acts Of God: How Cybercriminals Leverage AI To Exploit Breaking News

Presenter: Andre Piazza

How AutoSecT Delivers 80% Faster Pentesting and Better Budget Efficiency

Companies continue to add innovative apps, APIs, cloud services, and web-based solutions. This poses a larger security problem. Penetration testing, or pentesting, is one solution that assists security teams.

Securing Model Context Protocol (MCP) Deployments Against Quantum Computing Risks

Is your AI infrastructure vulnerable? Learn how to protect Model Context Protocol (MCP) deployments from Harvest Now, Decrypt Later quantum computing attacks.

Cyber Essentials Explained for Small Businesses

Cyber Essentials is the first cybersecurity standard UK SMEs usually hear about, focusing on common ways small businesses are affected by cyber attacks.

How You Actually Secure Systems: Using OWASP and NIST Together

OWASP and NIST get mentioned in the same breath, but they answer different questions. One tells you what to fix in your code; the other tells you how to run a security program. Here is what each framework actually does and how to use them together.

The World Cup Email Your Employees Will Actually Fall For

Your employees are not going to fall for a fake ticket site, most of them, anyway. Learn how fake FIFA storefronts and crypto-only "hospitality packages" are aimed at fans.

Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion

The Shai-Hulud campaign family is notable for how systematically it moved through the software supply chain trust stack: maintainer authentication, install-time execution, security tooling, provenance, OIDC-based publishing, developer tooling, and AI-assisted analysis. This evolution has highlighted vulnerabilities.

Key Developments

  • Miasma (March 2026): Expanded into PyPI through a compromised vulnerability scanner and introduced .pth-based persistence.
  • Hades (May 2026): Abused a GitHub Actions CI misconfiguration to scrape OIDC tokens.
  • IDE Wave (June 2026): Introduced prompt injection in PyPI packages to mislead LLM-based security scanners.