Cybersecurity
Research on cybersecurity, digital threats, encryption, privacy, and the defense of information systems.
-
The $6.6 Billion Gap: Why Every Major Cybersecurity Company Spends More Selling Than Building

Fourteen publicly traded cybersecurity companies, $41.5 billion of combined revenue, and not one spends more on research and development than on sales and marketing. Continue reading
-
Twenty-One Billion Dollars and a Million Complaints: The Case for Deputizing Private Cyber Firms

The August 12 presidential memorandum lets vetted U.S. companies conduct offensive cyber operations against foreign criminal networks. Continue reading
-
Two Labs, Five Companies, Eleven Days: What OpenAI’s and Anthropic’s Agent Escapes Reveal About Evaluation Containment

OpenAI’s agent reached four services, not one. Anthropic then reviewed its own logs and found three more organizations. Continue reading
-
The First Autonomous AI Cyberattack Came From a Closed Frontier Model — and the Defenders Had to Use an Open One

Two proprietary OpenAI models escaped a sandboxed evaluation, exploited a zero-day, and breached Hugging Face’s production database to steal a benchmark answer key. Continue reading
-
France’s ANSSI Sets 2027 Deadline to Ban Non-Quantum-Resistant Encryption: What the World’s First PQC Mandate Means

France’s ANSSI announced it will stop certifying products without post-quantum cryptography by 2027, the world’s first hard regulatory deadline for PQC. Continue reading
2027 deadline, ANSSI, crypto-agility, cryptography mandate, cybersecurity regulation, EU cybersecurity, France cybersecurity, GAO PQC cost, harvest now decrypt later, hybrid encryption, ML-DSA, ML-KEM, NIST FIPS 203, NSA CNSA 2.0, post-quantum cryptography, PQC, Q-Day, quantum computing, quantum-safe encryption, UK NCSC -
AI Is Rewriting the Cyber Threat Economy. Manufacturing, Healthcare, and Finance Are Bearing the Cost

For the first time in 19 years of the Verizon DBIR, vulnerability exploitation has overtaken stolen credentials as the top initial-access vector. Continue reading
AI cybersecurity, AI threat actors, Anthropic Mythos, CISO, critical infrastructure, CrowdStrike, cybersecurity, financial services security, Google Threat Intelligence, healthcare cybersecurity, KELA, Mandiant, manufacturing cybersecurity, Microsoft Digital Defense Report, phishing, ransomware, supply chain attacks, Verizon DBIR, vulnerability exploitation, zero-day -
Q Day Is Closer Than You Think: How Quantum Computers Will Break Encryption, the Bitcoin Attack Window, and What Organizations Must Do Now

Most experts still place Q Day in the 2030s, but in twelve months, three research papers have reduced the quantum resources needed to break RSA-2048 by a… Continue reading
