Ken here from Cyberse. Welcome to Secure (with Context), your no-BS guide to smarter security decisions.
Here’s what you get every week:
Top Stories in Cybersecurity 📰 — the news that actually matters, stripped of the vendor spin
Marketplace Changes 🔄 — what’s moving, what’s dying, and what you should actually care about
Trending Community Topics 🔥 — the conversations your peers are having in the forums this week (the real ones, not the astroturfed ones)
Hot Scoop at Cyberse 🍵 — what we’re building, learning, and occasionally complaining about
We cut through the hype. We help you find the creators worth following. We give you free tools to buy and build with confidence.
And yes, with the jaded dark humor you only get from someone who’s actually sat through the vendor pitch.
Subscribe for free. Tell a colleague who’s tired of recycled decks.
👋 Want to share this newsletter?
Criminals used an LLM to write a working 2FA bypass exploit. Educational docstrings, a hallucinated CVSS score, textbook-clean Python. Not how humans write exploits.
On May 11, Google’s Threat Intelligence Group disclosed that a criminal group used a large language model to build a zero-day exploit targeting a logic flaw in a popular open-source admin tool’s 2FA flow -- a hardcoded trust assumption that traditional vulnerability scanners routinely miss. Researchers identified it as AI-authored through structural markers no human team would leave behind. Google coordinated a patch with the vendor before the planned mass-exploitation campaign launched.
Here’s what changed on May 11. AI-assisted exploit development stopped being a threat intelligence prediction and became a confirmed operational capability in criminal hands. The attack targeted a semantic logic flaw -- the class of bug AI excels at finding because it requires understanding developer intent, not just memory patterns. Detection tools trained on human-written exploit patterns missed it entirely.
The 2026 Verizon DBIR, published nine days later, cited this case and noted that 28.3% of CVEs are now exploited within 24 hours of disclosure. Patch windows aren’t shrinking anymore. In some cases they’re already closed before you know the flaw exists.
Anyone running open-source admin panels, DevOps tooling, or web-based monitoring dashboards should audit exposure now. Any CISO telling a board that their signature-based detection stack covers AI-generated threats should be ready to explain exactly how that works.
Watch for: Whether other threat intelligence firms identify additional AI-built exploits in the coming weeks. A pattern signals a structural shift, not an isolated incident.
Source: Google GTIG / CNBC -- May 11, 2026
CVE-2026-0300. CVSS 9.3. Unauthenticated remote code execution. Root privileges. Internet-exposed firewalls. State-linked. Active since April 9. Patch available May 13. That’s 31 days.
That’s 31 days of open season on the device you put at the network edge specifically to stop this kind of thing.
Palo Alto Networks confirmed active exploitation of a buffer-overflow flaw in PAN-OS affecting internet-exposed PA-Series and VM-Series firewalls. Unit 42 attributed the campaign to threat cluster CL-STA-1132, described as likely state-sponsored. Exploitation began April 9 with initial attempts, progressed to successful nginx-worker shellcode injection by mid-month, and continued undetected for over a month before the first fix shipped on May 13. Cloud NGFW and Panorama were not affected.
The business question isn’t whether to patch. It’s whether you already have -- and whether anyone was inside before you got there.
Practical checklist: block management interface exposure immediately, audit captive-portal logs back to April 9, run Unit 42’s published IOCs against historical telemetry. Expect insurance carriers at renewal to ask whether you followed mitigation guidance before the patch was available.
Watch for: Post-patch exploitation rates, since attackers historically race the patch window, and any disclosure of which organizations CL-STA-1132 was actually targeting.
Source: BleepingComputer / Palo Alto Networks -- May 12, 2026
The Verizon DBIR has run for 19 years. For 19 years, stolen credentials topped the chart. The 2026 report ended that streak.
Verizon’s 2026 Data Breach Investigations Report, covering more than 12,000 confirmed breaches, found that vulnerability exploitation now accounts for 31% of all initial access vectors -- up from 20% the prior year. Credential theft still matters. It just doesn’t lead anymore.
The number behind the number: organizations remediated only 26% of CISA’s Known Exploited Vulnerabilities catalog in 2025. Down from 38% the year before. Attacker cadence is accelerating. Defensive capacity isn’t keeping up.
Two other numbers worth reading before your next board meeting. Third-party and supply-chain breaches are up 60% year-over-year and now represent 48% of all incidents. Ransomware appeared in 44% of analyzed breaches. AI is the accelerant across all of it.
Security programs built around MFA and identity hardening are not wrong. They’re incomplete. The budget conversation is no longer whether you need vulnerability management. It’s why you’re patching 26% of the list.
Watch for: Whether patch automation and AI-assisted vulnerability scanning vendors gain share against identity security platforms in H2 2026 purchasing decisions.
Source: Verizon DBIR 2026 / SecurityWeek -- May 19-20, 2026
One compromised extension. Eighteen minutes live on the marketplace. One GitHub employee who installed it. 3,800 internal repositories exfiltrated.
TeamPCP poisoned version 18.95.0 of the Nx Console VS Code extension on May 18. The compromised version was live on Visual Studio Marketplace for exactly 18 minutes -- 12:30 to 12:48 UTC. One GitHub employee installed it. The attackers got a foothold. More than 3,800 internal GitHub repositories were exfiltrated. GitHub confirmed the breach on May 20 and stated no customer data was taken. TeamPCP is reportedly asking $50,000+ for the stolen dataset on underground forums.
The attack chain: npm package compromise, to VS Code extension, to employee device, to internal codebase. It’s a template adversaries will replicate. The same TanStack supply chain attack also impacted OpenAI, Mistral AI, and Grafana Labs simultaneously.
Most enterprises let developers self-manage VS Code extensions. No vetting policy. No allowlisting. That’s not a future risk. The attack also carried valid SLSA provenance on malicious packages, meaning traditional cryptographic supply-chain trust mechanisms provided zero defense.
The fix isn’t complicated. IDE extension management needs the same procurement rigor applied to SaaS application approvals. It doesn’t have that yet. This is why.
Watch for: GitHub’s disclosure of exactly which internal repositories were affected and whether any production credentials or material source code surface in the stolen dataset.
Source: The Hacker News / GitHub -- May 20-22, 2026
The agency that tells the rest of the country how to handle credentials left its own on a public GitHub repository for half a year. Then left them valid for 48 hours after a researcher flagged it.
The repository was named ‘Private-CISA.’ It wasn’t. It contained highly privileged AWS GovCloud administrative access keys and a CSV file of plaintext usernames and passwords for dozens of CISA internal systems. The contractor was employed by Nightwing, a government cybersecurity services firm.
GitGuardian and Valadon flagged it on May 14 and 15. CISA took the repository down. The credentials remained valid and usable for 48 hours after takedown. Anyone who cloned the repo before removal had two full days to authenticate to GovCloud. Senator Maggie Hassan has opened a formal inquiry into CISA’s credential rotation procedures and incident response timelines.
The 48-hour response window after disclosure is the real failure. It’s the gap between ‘we noticed’ and ‘we closed it.’ If your contractor access control relies on contractors not committing secrets to public repositories, you have a process problem -- and this incident is a direct proxy test of whether your organization would catch the same thing.
Watch for: CISA’s formal congressional response and whether it triggers a government-wide contractor credentialing policy overhaul that cascades to private-sector contractors.
Source: Krebs on Security -- May 19, 2026
ServiceNow just dropped one of the largest cyber-asset graphs on the market into the Now Platform CMDB. Asset visibility is no longer a standalone security tool problem.
ServiceNow closed its acquisition of Armis and immediately integrated Armis’s asset graph for IT, OT, IoT, and IoMT into its existing Security Operations, IT Operations, and GRC product lines. Vulnerability, exposure, and risk data now flow through the same workflow engine most enterprise IT and security teams are already using. The combination covers what none of the standalone CAASM vendors can: the full asset map of record plus the business workflows attached to it.
The vendors feeling the squeeze: Axonius, JupiterOne, and every OT-focused point solution without a compelling ServiceNow integration story. If Armis capability lands inside existing SecOps SKUs -- which is exactly what ServiceNow is positioned to do -- the ROI argument for standalone tools becomes a conversation about what they do that ServiceNow doesn’t.
CISOs running point on attack surface management, exposure management, and OT visibility should expect their counterparts in IT and GRC to reach for ServiceNow-native answers first at the next budget cycle.
Watch for: ServiceNow’s pricing posture on the Armis integration. If capability lands inside existing licenses at zero incremental cost, standalone CAASM and OT vendors will have to defend ROI against a $0 alternative.
Source: ServiceNow Newsroom -- May 12, 2026
Humans, machines, workloads, AI agents. Palo Alto unified them all under a zero-standing-privilege platform built from a $25 billion acquisition.
Palo Alto Networks launched Idira on May 12, rebranding and extending its CyberArk acquisition into a next-generation identity security platform. Idira operates on a zero-standing-privilege model -- no persistent admin credentials, ever -- and dynamically assigns access rights using a centralized risk engine integrated across Strata, Cortex, and Prisma. The platform also absorbs the Koi and Portkey acquisitions, adding machine identity and AI-agent lifecycle management to what was already the market-leading PAM stack.
Every legacy PAM vendor -- SailPoint, BeyondTrust, Delinea -- is now competing against a platform that bundles identity into a $25 billion unified security stack. For CISOs, this accelerates the consolidation decision: standalone best-of-breed PAM versus identity as a native pillar of a fully integrated platform.
The agentic AI angle is the most urgent gap. Most organizations have zero policies governing credentials for AI agents. Idira addresses that exposure before regulators do. The CISO who brings this to a board conversation in 2026 is ahead of the curve. The one who doesn’t will get asked about it anyway.
Watch for: Whether Microsoft and CrowdStrike respond with competing acquisitions to match Palo Alto’s identity platform depth -- and whether Idira’s first joint pricing announcement triggers a wave of PAM consolidation conversations.
Source: SiliconAngle -- May 12, 2026
Eighteen months ago, non-human identity was a niche problem. Today it’s a $400 million acquisition. Cisco just put the first nine-figure price tag on the category.
Cisco announced its intent to acquire Tel Aviv-based Astrix Security for approximately $400 million. Astrix discovers and governs the non-human identities -- API keys, OAuth tokens, service accounts -- that AI agents now use to act inside enterprise systems. Cisco is folding Astrix into Cisco Identity Intelligence, putting NHI security on the same level as human identity for the first time.
The competitive signal is direct: every major identity vendor -- Okta, Microsoft Entra, BeyondTrust, SailPoint -- is under shorter-fuse pressure. This acquisition sets a benchmark valuation for a category that barely existed eighteen months ago and puts a credible Cisco-platform answer in front of CISOs evaluating AI agent rollouts.
Expect accelerated bundling pitches and re-priced renewals across identity portfolios over the next two quarters. The enterprise that hasn’t audited its non-human identity sprawl yet is the one most surprised by what that audit finds.
Watch for: Which identity-security pure-play gets acquired next -- and whether Microsoft answers with an Entra Agent module to compete directly with Cisco’s combined NHI story.
Source: SecurityWeek -- May 14, 2026
Investors committed $125 million to a company arguing that AI agents can handle 90% of what tier-1 SOC analysts do -- faster, and without the headcount.
Exaforce raised $125 million from HarbourVest, Peak XV, Mayfield, Khosla Ventures, and Seligman Ventures. Total funding: $200 million. Valuation: $725 million. The platform pairs a real-time security knowledge graph with AI agents -- called Exabots -- that handle triage, investigation, and response autonomously. A new capability called ‘vibe hunting’ lets analysts investigate threats via plain natural-language queries. Current enterprise customers include Replit and Guardant Health.
Combined with Microsoft’s MDASH launch the same week, the bar for SOC modernization in 2026 is now an agent that can close alerts without waiting for a human. Traditional SOC automation vendors should expect that framing in every competitive RFP.
For buyers evaluating SOC modernization, this funding creates a credibility anchor: Exaforce now has the runway to compete for enterprise deals against entrenched incumbents. The natural-language query interface also lowers the bar for smaller teams operating without deep SIEM expertise.
Watch for: A major enterprise SIEM displacement win that demonstrates Exaforce can unseat incumbents in competitive accounts -- not just land greenfield opportunities. That announcement defines the category.
Source: TechCrunch / SecurityWeek -- May 12-13, 2026
A startup founded by two IDF Intelligence Corps veterans exited stealth with $28 million. Their thesis: the only way to beat AI-generated phishing is an AI that reasons like a security analyst on every single email.
Ocean -- backed by Lightspeed and Picture Capital, with notable angels including Wiz CEO Assaf Rappaport and Armis co-founders -- deploys AI agents that analyze every inbound message in real time. Sender identity, message content, organizational context, embedded links. Not pattern-matching. Not signatures. Reasoning. One billion emails processed in year one. Hundreds of thousands of mailboxes secured at Fortune 500 clients including Kayak, Kingston, and Headspace.
Legacy Secure Email Gateway vendors built their products on signature-based detection. AI-generated phishing defeats that approach by design -- it writes new content every time. The vendor that figured out phishing signatures now has a structural disadvantage against the attack they were built to stop.
Ocean’s $28M at meaningful scale confirms investors are paying full price for AI-native positioning. The enterprise email security market is entering a disruption cycle. Any CISO renewing an email security contract in 2026 should benchmark against AI-native platforms before signing.
Watch for: Whether Proofpoint, Abnormal Security, or Microsoft Defender for Office 365 respond with accelerated AI roadmaps or acquisitions -- and whether Ocean publishes a head-to-head benchmark against incumbents.
Source: GlobeNewswire -- May 19, 2026
🚨 We finally added an About Us page to our Cyberse website and it feels like an important milestone.
Cyberse started with a simple idea. Make cybersecurity easier to understand, easier to evaluate, and easier to buy without the noise, pressure, or vendor bias that dominates the industry.
The new About Us page shares more about why we built Cyberse, who it is for, and how we think about community, independent expertise, and practical decision making for security leaders.
If you are curious about the mission behind the marketplace or want a bit more context on where we are headed, it is worth a look.
🔗: About Us
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.