Most security content keeps you informed.
SKB Decoded keeps you sharp.
Every week I break down one real attack, one defense failure, and how AI is changing the threat landscape.
Free. Weekly. No fluff.
π Subscribe here
https://t.co/t7Ja2CWZdL
Below the line (provider's job):
physical servers, data centers,
core network, the layer that
walls off your data from other
customers'.
They're extraordinarily good
at this part.
A researcher finds a company's
entire customer database sitting
in a cloud storage bucket.
Unprotected. Reachable by anyone
with the link.
No hacking. No exploit π§΅
Above the line (yours):
your data, access permissions,
configs, identity management,
which storage buckets are public
vs. private.
The provider locks the building.
You lock your own apartment door.
The misunderstanding: "the cloud"
isn't a place. It's a rented
arrangement with a dividing line
through it.
That line has a name: the shared
responsibility model.
A researcher finds a company's
entire customer database sitting
in a cloud storage bucket.
Unprotected. Reachable by anyone
with the link.
No hacking. No exploit π§΅
A setting, left on its default,
had simply never been changed
by anyone.
That's the plot behind a huge
share of the biggest cloud
breaches of the last 2 years.
A market doesn't get arrested.
Wrong question: "could a skilled
hacker breach us?"
Right question: "which specialized
role in this supply chain could
reach us?"
Jan 2026: US law enforcement seized
RAMP, a major forum connecting IABs,
affiliates, and RaaS operators.
Activity dipped for weeks.
It's already resurfacing under new
names.
Around the core: packer services to
dodge antivirus, bulletproof hosting,
money-laundering specialists.
And real customer support β scripts,
live chat, decryption-testing tools.
One group, "The Gentlemen," offers
affiliates a 90% cut β specifically
to poach talent from rival platforms.
Affiliate recruitment, run like a
sales incentive.
Initial Access Broker.
Breaks into networks. Doesn't touch
them further. Sells the access for
$500β$5,000 on criminal forums.
Made $14M+ in 2025 doing only this.
A hospital's files get encrypted.
The ransom note has a link to live chat.
They open it expecting silence.
Instead: a support rep, replying in minutes, walking them through paymentπ§΅
An Uber contractor gets a login approval request.
He declines it.
Another. Decline. Another β every few minutes,
for over an hour.
Exhausted, he finally taps approve just to
make it stop.
Attacker is in. Slack, VPN, source code π§΅
An Uber contractor gets a login approval request.
He declines it.
Another. Decline. Another β every few minutes,
for over an hour.
Exhausted, he finally taps approve just to
make it stop.
Attacker is in. Slack, VPN, source code π§΅
The shift:
Every dependency is a trust decision you made
without realizing it.
Trust extended is risk inherited.
Full breakdown (free): https://t.co/BhNBFORNr6
#Cybersecurity#SupplyChainSecurity
In September 2025, a piece of malware did something new:
It copied itself.
A poisoned software package spread on its own across
1,000+ packages β and exposed ~25,000 code repositories
downstream.
Nobody hacked them. They installed it themselves π§΅
The invisible part:
6 companies use the same accounting software.
None can see that shared dependency from their own
vendor list.
But to an attacker, it's one door with 6x the payoff.
Invisible to every victim. Obvious to the attacker.