Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICISA Issues Fresh SBOM Guidance. Did They Get It Right?
CISA has released updated guidance on Software Bill of Materials (SBOM) that introduces approximately two dozen changes to SBOM fields aimed at improving comprehensiveness. However, critics contend that while the updates enhance data collection, they fall short of delivering meaningful improvements to risk management capabilities.
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System agreed to pay $552,250 to settle a HIPAA investigation following a 2021 Nephilim ransomware attack that compromised the protected health information of 53,907 patients. The OCR investigation found OSF Healthcare failed to conduct proper risk analysis, made impermissible PHI disclosures, and did not provide timely breach notifications to affected individuals and HHS. The settl
AIFree Webinar: Inside 250 HIPAA Investigations – What You Need to Know
Abyde is hosting a webinar featuring insights from over 250 actual OCR HIPAA investigations, led by their Chief Legal Officer and Senior VP of Operations. The session will cover investigation triggers, response protocols, common compliance failures, and real-world examples to help healthcare organizations avoid fines and lengthy investigations in an era of increasing ransomware breaches and patien
Measuring LLMs’ Ability to Perform Cryptanalysis
A new benchmark called CryptanalysisBench tests LLMs' ability to discover mathematical cryptanalytic attacks against 191 historical cryptographic primitives. Frontier models from Anthropic, OpenAI, and others successfully broke 65-86% of known-vulnerable schemes and discovered novel attacks, including previously unknown vulnerabilities in SpoC AEAD and KINDI's security proof. This represents an em
AIHow to Become HIPAA Compliant
This article outlines a practical framework for achieving HIPAA compliance based on HHS's Seven Fundamental Elements of an Effective Compliance Program, updated for 2026 relevance. The approach emphasizes developing comprehensive policies, designating compliance officers, implementing effective training, establishing communication channels, monitoring practices, enforcing sanctions fairly, and res
AICISA Instructs Federal Agencies to Adopt Risk-Based Approach for Vulnerability Remediation
CISA has issued Binding Operational Directive (BOD 26-04) requiring federal civilian agencies to adopt a risk-based vulnerability remediation framework with tiered patching deadlines. The directive addresses the growing challenge of vulnerability management, as AI-accelerated vulnerability discovery has overwhelmed defenders, with remediation rates dropping from 38% in 2024 to 26% in 2025. The new
AIThe Invisible Battlefield: How Cyber War Is Reshaping Everyday Life
Former National Cyber Director Chris Inglis highlights the escalating threat of cyber attacks targeting critical infrastructure including hospitals, utilities, and essential services. These attacks represent an invisible battlefield that increasingly impacts everyday operations and public safety, requiring heightened awareness and defensive measures from enterprise organizations.
HSCC Issues Guidance on Cyber Governance Frameworks for Secure AI implementation
The Health Sector Coordinating Council (HSCC) has released comprehensive guidance to help healthcare CISOs establish cybersecurity governance frameworks for secure AI implementation. The 87-page framework addresses AI-specific cyber risks including data poisoning, model drift, and bias, while providing practical tools for managing AI systems throughout their lifecycle from assessment to decommissi
AICyber Insurance Rates Are Dropping, but Exclusions Widen
Cyber insurance premiums are declining as the market stabilizes, but insurers are simultaneously broadening policy exclusions. Notably, some policies are now excluding coverage for social engineering attacks such as ClickFix, potentially leaving organizations exposed to increasingly sophisticated fraud schemes.
AIAsia's Cyber Insurance Market Shows Signs of Life
Asia's cyber insurance market, which has historically lagged behind other regions due to various barriers, is beginning to show signs of growth and increased adoption. The market's previous weak penetration is now shifting as organizations recognize the need for cyber risk coverage.
Chilling Effects
Academic experts argue that the Trump administration is systematically employing 'chilling effects'—using surveillance, threats, arrests, and deportations—to suppress dissent and create widespread self-censorship among students, professors, media, and other institutions. This strategy, evident across multiple domains from campus activism to journalism, mirrors historical tactics used during the Mc
AIFocus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
This article examines how cyber insurance is driving organizations to adopt more rigorous risk quantification practices in their security programs. The discussion covers the scope of cyber insurance coverage, including notable exclusions, and explores how insurance requirements may be catalyzing positive changes in enterprise cybersecurity strategies.
AIFrom Stuxnet to ChatGPT: 20 News Events That Shaped Cyber
Dark Reading commemorates its 20th anniversary by identifying 20 pivotal cybersecurity news events from the past two decades that have fundamentally shaped today's enterprise threat landscape. The retrospective spans from landmark incidents like Stuxnet to emerging AI-driven security challenges exemplified by ChatGPT, illustrating the evolution of cyber risks facing modern organizations.
