Resilient Cyber
Cybersecurity, Cloud, DevSecOps and Software Supply Chain Security
- Indexed issues, last 90 days
- 17
- Latest publication
- Sep 29, 2026
- Audience
- Checking…
- Earliest in this view
- Aug 25, 2026
Latest issues
The Workforce Identity Gap: What It Costs to Leave It Open (opens the original)
Read excerpt
I don’t think any practitioners would debate that identity has become a dominant initial access vector for attackers, with several years of incident response data and headline breaches pointing in the same direction. The industry spent two decades hardening the perimeter, pursuing approaches such as Zero Trust, and attackers responded by simply acquiring a working credential and walking through the front door as a legitimate user.As the saying goes, hackers don’t hack in, they log in.That said,
Cybersecurity is Ceding AI Safety, But Should We? (opens the original)
Read excerpt
In this episode, I sit down with , CEO and co-founder of AI agent monitoring startup Embroidery and former CTO of a cybersecurity company, to unpack the collision between the AI safety world and the cybersecurity world that has played out since the OpenAI Hugging Face incident. I first found Zack during the fake SOC 2 report saga on X, and his videos on effective altruism and on the METR and Redwood Research review of the incident have been among the sharper practitioner critiques I’ve read. Tha
Zero Trust for AI Systems (opens the original)
Read excerpt
It’s no secret that I’m a fan of content from the Coalition for Secure AI (CoSAI). I previously referenced their excellent publication on Agentic IAM for a blog, and interviewed the authors on the Resilient Cyber podcast. Now, they recently released a great whitepaper on Zero Trust for AI systems and I wanted to take sometime to walkthrough it here, because despite all the hype and media narrative of existential risks, most of the cyber risks related to AI are tied to cybersecurity f
Resilient Cyber Newsletter #115 (opens the original)
Read excerpt
Welcome to issue #115 of the Resilient Cyber Newsletter!This week the cost side of offense got very concrete. Gambit documented a criminal running three open source agent frameworks against online retailers at a mean of $25.46 per target, and Hacktron walked from OpenAI’s community forum to its internal repos in under 72 hours for less than $3,000 in tokens. The WSJ also reported that Gemini broke out of a test harness and into three real companies back in May. On the other side of the ledger, G
AI Code Security and the Independent Control Plane (opens the original)
Read excerpt
In this episode, I sit down with Checkmarx Chief Product Officer Jonathan Rende to discuss where AppSec stands now that AI coding tools are standard in the enterprise. We cover why he argues a model can’t be its own security control and what Checkmarx’s benchmarking shows about combining rules-based and AI-driven scanning.Jonathan worked in software quality and developer tooling before coming back to security, going back to the Fortify and SPI Dynamics days. He has seen a few platform shifts up
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.