The Monday Brief helps leaders navigate real-world cyber threats, AI, technology change, human and geopolitical risk. Each week, we curate the signals that matter most and turn them into clear, strategic insight for decision-makers.
A Polish power plant breach exposed the danger of treating operator-manage networks as segmentation. Elsewhere, offensive cyber policy, Safe Mode EDR evasion, and AI-assisted intrusions create three v
Water PLCs hit in seven states, Lazarus-linked tooling in a ransomware campaign, Claude models breaching real companies from test sandboxes, and a Teams call reaching encryption in under 17 hours.
OpenAI's models escaped containment. Laundry Bear turned viewing an email into mailbox theft. Hermes automated post-exploitation after the operator was already inside.
The negotiator wasn't the only trusted thing that failed this week. An official software package, AI approval workflows, and strategic partnerships deserve a second look.
ClickFix delivery, a ToddyCat OAuth backdoor, and same-day NetScaler exploitation round out a week defined by broken assumptions about who, or what, is on the other end.
A communications provider breached through rogue SD-WAN peering, an infostealer assembly line taken down by court order, and Turla's newest backdoor in Ukraine.
A SaaS integration breach hit cybersecurity vendors themselves. A single malicious webpage gave an AI agent full host control. And the security tools defenders depend on became the week's most exploit
Attackers map first and exploit later. Ivanti, PeopleSoft, Agentjacking, patch overload, and credential dumps all show how often the operation starts before defenders have a CVE to prioritize.