Breach of Confidence — 12 June 2026
This week I think I’d like a refund on my optimism. The Doxxer Gets Doxxed Someone in Spain leaked the personal details of police, prosecutors, and cyber officials across multiple platforms. They got arrested in Granada last week. The poetic justice of doxxing the very people tasked with preventing doxxing is absolutely chef’s kiss. Read more in the Breach of Confidence — 12 June 2026 article.
Mythos 5 Restricted by US Government for Being Too Dangerous
For those of you who have been questioning the power and impact of Mythos, claiming the initial restricted use (Project Glasswing) was just a marketing ploy, I urge you to reconsider and listen to cybersecurity experts.
The Mythos Effect is real. It is a signal of change across the industry, forced by the order-of-magnitude performance in finding and exploiting vulnerabilities by a new generation of AI models (soon from several vendors).
Anthropic is acting ethically, but unfortunately, such performance gains cannot be contained for long. Every major AI vendor is pursuing this level of competency, which impacts security capabilities to respond and close weaknesses before they are exploited. Here are some articles to come up to speed:
- Mythos Is Rewriting the Rules of Cybersecurity – published May 1st
- How Mythos Signals Cybersecurity Disruption – published May 4th
- AI Will Exploit What Businesses Refuse to Fix – published May 19th
- Cybersecurity Must Prepare for AI Driven Hardware Exploitation – published May 20th
- Anthropic AI Security Framework is a Start but Fails to Deliver – published Jun 1st
- The Mythos Effect is Rewriting the Rules of Cybersecurity – published June 9th
Saturday Security: CISA’s New 72-Hour Patch Rule
For years the mantra in IT security has been simple — patch everything. But in the age of AI that’s no longer realistic. And this week CISA made it official with a new approach that changes the game for federal agencies and sets a precedent for the entire industry.
BSides Seattle 2026 – Acts Of God: How Cybercriminals Leverage AI To Exploit Breaking News
Presenter: Andre Piazza
How AutoSecT Delivers 80% Faster Pentesting and Better Budget Efficiency
Companies continue to add innovative apps, APIs, cloud services, and web-based solutions. This poses a larger security problem. Penetration testing, or pentesting, is one solution that assists security teams.
Securing Model Context Protocol (MCP) Deployments Against Quantum Computing Risks
Is your AI infrastructure vulnerable? Learn how to protect Model Context Protocol (MCP) deployments from Harvest Now, Decrypt Later quantum computing attacks.
Cyber Essentials Explained for Small Businesses
Cyber Essentials is the first cybersecurity standard UK SMEs usually hear about, focusing on common ways small businesses are affected by cyber attacks.
How You Actually Secure Systems: Using OWASP and NIST Together
OWASP and NIST get mentioned in the same breath, but they answer different questions. One tells you what to fix in your code; the other tells you how to run a security program. Here is what each framework actually does and how to use them together.
The World Cup Email Your Employees Will Actually Fall For
Your employees are not going to fall for a fake ticket site, most of them, anyway. Learn how fake FIFA storefronts and crypto-only "hospitality packages" are aimed at fans.
Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion
The Shai-Hulud campaign family is notable for how systematically it moved through the software supply chain trust stack: maintainer authentication, install-time execution, security tooling, provenance, OIDC-based publishing, developer tooling, and AI-assisted analysis. This evolution has highlighted vulnerabilities.
Key Developments
- Miasma (March 2026): Expanded into PyPI through a compromised vulnerability scanner and introduced .pth-based persistence.
- Hades (May 2026): Abused a GitHub Actions CI misconfiguration to scrape OIDC tokens.
- IDE Wave (June 2026): Introduced prompt injection in PyPI packages to mislead LLM-based security scanners.