🔥 Amazing day at the @SANSInstitute#AISummit 2026.
I had the chance to join the SANS360 lightning talks. 10 practitioners, 6 minutes each. No fluff.
My message was simple: #AI is collapsing prevention time, but time-based security still holds. Speed doesn’t make these attacks smarter. In fact, it often makes them more fragile.
To show how #AllAroundDefenders can flip the script, today we introduced #Decipio, our latest community project from the @AWNetworks Labs team.
#Decipio injects controlled “lies” into the environment to expose credential theft the moment it begins. It also applies automation and AI-assisted workflows defensively, creating a home-field advantage for defenders.
To protect the #cyberdefense community, we decided to release Decipio as a gated, community-driven release.
👉 You can start requesting access today through our website, and learn more about it in our latest blog:
🔹 https://t.co/IkiXWyiwbE
🔹 https://t.co/ADXE2L9MQU
#CyberDefense #AI #ThinkRedActBlue
Thanks to @Bloomberg for covering our latest @AWNetworks#LightSpy research: a Chinese-built #spyware platform operating in more than 13 countries, with 117 servers, router implants across Europe and Africa, pricing tiers, billing infrastructure, even a demo environment for prospective buyers. Surveillance sold as a product, complete with customer service.
The best detail: an operator used the platform's own billing infrastructure to order KFC, leaving his real name and office address behind. Even nation-state operators get hungry. This one's OPSEC was finger lickin' bad 🍗
Full story: https://t.co/aK3hFW4E5T
#ThreatIntelligence #LightSpy #Spyware #BlackHat2026 #ArcticWolf
25+ years in this field and the findings have not changed: weak passwords, no network isolation, exposed services nobody inventoried.
What changed this week is who found them. Anthropic's own AI models breached three real companies from a test sandbox. A vishing crew went from a Teams call to ransomware in 17 hours. Someone edited water PLC safety logic in seven states with the vendors' own engineering tools.
None of them needed an exploit, because the basics were already broken.
Think Red by @fulmetalpackets. Act Blue by @aboutsecurity.
https://t.co/4fgXCksthD
#CyberSecurity #ThreatIntelligence #OTSecurity #BlueTeam #InfoSec #SOC #Ransomware
Everyone covered the #OpenAI sandbox escape last week. Two stories got almost no attention.
1/ Sixteen countries signed a joint advisory on a Russian campaign against Zimbra webmail. Laundry Bear. Targets across NATO states, Ukraine and the US, including nuclear installations. Opening the message is enough. The part nobody covered: the payload issues itself an app-specific password and turns IMAP on. Reset every password in the tenant and the adversary is still reading mail. Patch to 10.1.20. Then go audit those credentials.
2/ An operator already inside Thailand's Ministry of Finance ran an open source agent unattended to handle privilege escalation checks and enumeration. Nothing exotic. The approval prompt meant to prevent it is one toggle. If isolating a host in your environment needs a human signature, their clock is faster than yours.
@spovolny of @exabeam joins @fulmetalpackets and @aboutsecurity on all three signals this week 👇
https://t.co/NqqNJc8tcX
#ThinkRedActBlue #ThreatIntelligence #ZeroTrust #AgenticAI
The AI "escaped the sandbox and gained internet access" is a fancy way of saying nobody enforced default deny outbound across the environment. Once again, this frontier AI lab story is less about a "superintelligent breakout" and more about a lack of cyberdefense fundamentals: a flat network with an egress path nobody was watching.
And yes, I know, a zero-day was involved. But zero-days get you code execution. A defensible security architecture decides what code execution gets you.
#DefensibleSecurityArchitecture #ZeroTrust #AllAroundDefender #SEC530
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.
Great conversations do not need a script. Just two friends who happen to think about adversaries for a living.
I joined my good friend and @TheMondayBrief co-host @fulmetalpackets at The War Room of Hackticks & Telemetry, to talk about the #ThinkRedActBlue strategy, @SANSDefense #SEC530, agentic AI threats, mitigations, and threat modeling, among other interesting things, including the World Cup, and the lessons learned of @MalagaCF promoting to 1st division with a bunch of kids, the importance of hard work and staying humble! ⚽ 🇪🇸
My segment starts around the 25 minute mark, but the whole conversation is worth your time 👇
https://t.co/wWXi0x9eDr
Thanks @fulmetalpackets and @rapid7 for having me on the show!
#ThreatIntelligence #Cybersecurity #TheMondayBrief #ThinkRedActBlue #InfoSec #CyberDefense #Malaga @SANSInstitute
An AI agent ran a full ransomware kill chain last week. No human at the keyboard.
@sysdig calls it JADEPUFFER, but it rode year-old CVEs and left signals everywhere. The shift isn't smarter attacks, it's cheaper ones.
New issue of @TheMondayBrief today with @fulmetalpackets, ft. John Hubbard @SecHubb@SANSDefense 👇
https://t.co/T54edd9cE1
#ThinkRedActBlue #BlueTeam #AI #Ransomware
This week's attacks did not beat a perimeter. They walked through doors already open.
OAuth tokens. Localhost services. Security tools treated as safe. The thread: trust that outlived its inspection.
By @aboutsecurity and @fulmetalpackets. This week featuring guest @GregoryR.
Every Monday in your inbox. Subscribe free
https://t.co/gVetZQdHHn
#ThinkRedActBlue #TheMondayBrief
This week in @TheMondayBrief we dig into a pattern that is easy to miss: the work attackers do before any advisory drops. Ivanti Sentry, the PeopleSoft campaign against universities, Agentjacking, a record Patch Tuesday. Different stories, same lesson: the exploit is rarely the starting point.
What makes this issue special is our guest. I am thrilled to welcome Thomas Roccia (@fr0gger_) to share his perspective on securing AI agents and the risks agentic systems introduce.
If you're not subscribed yet, this is a great week to start, so it lands in your inbox every Monday 👇
https://t.co/tzaslPlTST w/@fulmetalpackets
#ThinkRedActBlue #TheMondayBrief #ThreatIntelligence #AISecurity #CyberSecurity
Attackers do not need the vulnerability first. They need the map.
This week: Ivanti Sentry, ShinyHunters vs PeopleSoft, Agentjacking, a record Patch Tuesday, plus guest commentary from Thomas Roccia (@fr0gger_) on securing AI agents.
👇Subscribe and never miss a Monday.
https://t.co/OAcdA5VfKC
By @fulmetalpackets and @aboutsecurity
#ThinkRedActBlue #TheMondayBrief
This week's @themondaybrief marks a first: our debut guest perspective, and Vicente Diaz (@trompi) opens the series.
The theme this week is cost inversion. Attackers are borrowing the tools we already trust. As Vicente said in his commentary: "we've seen this movie before." The techniques aren't novel. The speed and scale are.
https://t.co/n8vtr7GvVu
#ThinkRedActBlue #TheMondayBrief w/ @fulmetalpackets
New Monday Brief is live.
This week the attacker's R&D budget shrank while your attack surface grew. Tricked AI bots, automated EDR evasion, a Claude Code repo takeover, and fake recruiters. No zero-days needed.
Plus a first for us: our debut guest perspective, featuring the great Vicente Diaz @trompi
Douglas McKee (@fulmetalpackets) thinks 🔴
Ismael Valenzuela (@aboutsecurity) 🔵
Vicente Diaz (@trompi) adds the threat intel lens 🔍
https://t.co/RN8kOJ9sHt
#ThinkRedActBlue #TheMondayBrief
You've been muted...permanently.
Thanks @bittner and N2K | CyberWire for having me on your show to talk about our latest @AWNetworks research on #BlueNoroff targeting #crypto and #Web3 executives.
Check it out here👇🏼
https://t.co/JLEuReH1DC
Arctic Wolf has observed a significant expansion of the phishing-as-a-service operation #Kali365, which abuses Microsoft’s OAuth device authorization flow to bypass MFA.
More details here: https://t.co/B8Y5RFWIFT