AI Will Change Cybersecurity. Humans Will Define Its Success. A Lesson No Algorithm Can Teach

An organization with mature, AI-driven security tooling stalled because ownership disputes and misaligned perceptions of risk prevented decisive action. Reframing technical findings into business impact, benchmarking against peers, and empowering trusted advisors restored accountability and drove remediation. #Sygnia #IsraelNationalCyberDirectorate

Read More
NTLM Reflection Attack

Attackers abuse misconfigured Unconstrained Delegation and NTLM reflection/relay to coerce high-value systems into authenticating to attacker-controlled hosts, allowing capture of Kerberos TGTs and escalation from a low-privileged user to full domain compromise without any software zero-day. Effective mitigations include enforcing SMB signing, disabling unconstrained delegation, restricting NTLM, and monitoring Kerberos/DCSync activity. #UnconstrainedDelegation #NTLMRelay

Read More
Privacy & Cybersecurity #65

This roundup summarizes recent national and subnational laws and regulatory guidance shaping data, AI, and communications security across Germany, the UK, Poland, multiple U.S. states, and the FCC. Key developments include Germany’s Data Act Implementation (DADG) with BNetzA enforcement, updated ICO ADM guidance, Poland’s KRiBSI AI supervision draft, California’s Executive Order N‑5‑26 on AI procurement, Utah’s SB 73 age‑verification and SEDI initiatives, New York’s S8828 frontier model rules, and the FCC’s addition of foreign‑made consumer routers to its Covered List. #DADG #ICO

Read More
Hardcoded Secrets in AI-Generated Code: Catch Them Before Git Does

AI coding models frequently insert hardcoded credentials into generated code because they learned “working” patterns from public repositories, which puts secrets into source files, git history, and client-side bundles. Prevent with a fast pre-commit scanner and deep-history verification—Gitleaks blocks commits while TruffleHog scans history and verifies live credentials to prioritize rotation. #Gitleaks #TruffleHog

Read More
The Biggest Supply Chain Attack of 2026 Was Unfolding While We Were at RSAC, the FBI Director’s Gmail Got Popped, and a B AI Startup’s Biometrics Hit the Auction Block

This issue of The Cybersecurity Pulse details a massive software supply-chain campaign by TeamPCP that poisoned widely used open-source security and runtime tools, triggering cascading compromises and exposing sensitive data from downstream victims. It also summarizes RSAC 2026’s focus on agentic AI—dozens of product launches and large funding rounds—while highlighting high-impact incidents like the Mercor breach, Codex command-injection, Handala’s Gmail compromise, and Intoxalock’s outage. #TeamPCP #Mercor

Read More
Kerberos Constrained Delegation Exploitation

This article provides a step-by-step technical walkthrough of abusing Kerberos Constrained Delegation (KCD) with Protocol Transition (S4U2Self + S4U2Proxy) in Active Directory to impersonate high-privilege users and access a SQL Server. It demonstrates exploiting a misconfigured service account (kavish) using tools like Impacket and outlines detection strategies and mitigations for defenders. #KerberosConstrainedDelegation #Impacket

Read More
Cybersecurity Can Learn from the Artemis Launch

The Artemis II mission successfully launched today, marking a major milestone in returning humans to the Moon and showcasing a world-class team’s management of immense risks. Cybersecurity can learn from this achievement by adopting strategic capabilities—prediction, prevention, detection, and response—with clear objectives, resources, accountability, and continuous feedback to build an enduring defense. #ArtemisII #NASA

Read More
Which Code Vulnerabilities Actually Get Fixed? New Code Security Data from 50,000+ Repos

Semgrep’s Remediation at Scale report analyzed remediation patterns across 50,000+ repositories in 2025 and found large, category-specific fix-rate gaps between high-performing “leaders” and the rest (“field”). The biggest gaps are in OWASP categories that require architectural changes—especially Authentication Failures and Cryptographic Failures—and leaders close more issues by using PR-level scanning, blocking rules, reachability analysis, and a 90-day escalation policy. #Semgrep #OWASPTop10

Read More
Workshop Resources: OWASP Threat and Safeguard Matrix (TaSM)

The Cybersecurity Club hosted a global workshop led by Ross Young to introduce OWASP’s Threat and Safeguard Matrix (TaSM), a practical framework that maps material threats to safeguards aligned with the NIST Cybersecurity Framework. Attendees worked through phishing, ransomware, web application attacks, third‑party data loss, and AI data‑leak scenarios involving ChatGPT and Google Gemini to identify coverage gaps, prioritize investments, and explore AI automation from Clear Capabilities. #OWASP #TaSM #RossYoung #ClearCapabilities #ChatGPT #GoogleGemini #NIST

Read More
Gemini 0.37%, Claude 0.25%, Grok 0%. Humans Destroyed Them All: ARC-AGI-3

ARC-AGI-3 is an interactive benchmark that drops agents into novel 64×64 grid environments with no instructions, exposing that frontier models score below 1% while humans solve 100% of the tasks. Anthropic’s Claude Dispatch ships the ability for a phone to control a live desktop Claude session with full filesystem reach, amplifying prompt-injection risk and highlighting that these models lack the abstract reasoning needed to safely interpret adversarial context. #ARC-AGI-3 #ClaudeDispatch

Read More