Posts

Featured Post

153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story

Image
Breaking Vendor Risk September 2026  ·  7 min read 153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story. This week, a database of more than 170 million scanned identity documents — driver's licenses, ID cards, travel documents — surfaced for sale, reportedly traced to a single identity-verification company whose scanning equipment sits behind the counter at car rental desks, hotels, casinos, and age-restricted retailers across North America. The company hasn't confirmed the breach. The FBI has opened an investigation. But the part of this story that matters most for small businesses isn't who got breached — it's a gap in the rules that most businesses scanning a customer's ID have never thought to ask about. Late last week, researchers investigating a dark-web identity-theft marketplace found something unusually l...

Software Vendors Just Shipped Records Numbers of Security Patches. Your Patch List Didn't Get Longer by Accident.

Image
Trend Report Patch Management August 2026  ·  8 min read Something changed in how software vulnerabilities get found this year, and the numbers are startling: disclosed flaws are on pace to roughly double last year's already-record total, and the biggest names in software have each shattered their own patch-count records, sometimes by five times over. The cause isn't sloppier code. It's that the tools doing the looking got dramatically better — on both sides of the fight. Here's what's actually happening, and why the way you decide what to patch first matters more now than it ever has. If your IT provider has seemed busier than usual with updates this year, that's not your imagination, and it isn't a coincidence specific to your systems. Something structural shifted in how software vulnerabilities get discovered in 2026, and the scale of it is large enough that security researchers are describing it as...

The US Department of Homeland Security Was Warned About a Breach — Twice — Before It Happened. Both Times, Someone Decided It Was Nothing

Image
Case Study Alert Fatigue August 2026  ·  7 min read The US Department of Homeland Security Was Warned About a Breach — Twice — Before It Happened. Both Times, Someone Decided It Was Nothing. In May 2026, security systems flagged intruders inside a major federal information-sharing network. An analyst looked, and decided it was nothing. Roughly a week later, the same intruders returned, and got flagged again. An analyst looked, and decided it was nothing a second time. Three weeks after the first alert, the breach was finally confirmed — backdoors installed, credentials stolen. This isn't a story about a missing alarm. The alarm went off twice. It's a story about what happens after it does. Most breach stories in this series describe a gap in defenses — a password nobody changed, a device left exposed, a warning that never arrived. This one is different, and in some ways more unsettling, because nothing was missing. ...

69% of Ransomware Victims Refused to Pay Last Year — the Highest Rate Ever Recorded. Here's What Changed.

Image
Good News What's Working August 2026  ·  7 min read Most of what this series covers is a warning. This one isn't. New research shows that more businesses said no to ransomware demands last year than at any point on record — and the reason isn't luck. It's preparation, catching up. Here's the record-breaking number, and a look back at every quiet win this series has documented this year that never made a scary headline. Ransomware coverage tends to follow one shape: the number of attacks goes up, the story gets written, everyone feels a little worse about the internet. That shape is accurate as far as it goes — attacks are up. But it leaves out the half of the story where businesses are winning, quietly, in ways that don't make headlines because nothing dramatic happened. This post is about that half. Verizon's newest global breach research, drawing on real incident data from the past year, found ...

One in Four Breaches Is Now AI-Enabled. Here's Every Way That's Shown Up in This Series.

Image
New Research Synthesis August 2026  ·  8 min read For most of this year, the AI-powered attacks we've covered read like isolated, almost freakish stories — a subscription phishing kit, a ransomware attack that fixed its own error in 31 seconds, an email assistant that helped rob its own employer. IBM's newest global breach research shows they were never isolated. One in four malicious breaches now involve AI, up 56% in a single year, and they cost businesses a million dollars more than an ordinary breach. Here's the number, and every place it's already shown up in stories we've told this year. Every time this series has covered an AI-related attack, there's been an implicit question sitting underneath it: is this a genuine trend, or a handful of striking anecdotes that make for a good headline? A subscription phishing kit is alarming. So is a ransomware attack that fixes its own mistakes. But two or three ...