CISO Debriefs — When AI Attacks

Intelligence Briefings for Security Leaders

CISO DEBRIEFS

Practitioner-grade analysis of AI threats, governance failures, and the attack patterns your board needs to understand.

#08
RANSOMWARE

Ransomware & Recovery Integrity

Ransomware + AI

Old ransomware encrypts your data and you restore from backup. This one poisons your agent mesh — and no backup contains a clean version of every decision your agents already made and propagated.

July 17, 2026Read More
#07
MACHINE

Identity Governance & Machine Credentials

Non-Human Identities

A service account with a long-lived token, scoped to everything and owned by no one, leaks in a forked repo. An attacker assumes the agent’s identity, mints fresh tokens, and reads every customer record.

June 19, 2026Read More
#06
SHADOW

Agentic Governance & Shadow Infrastructure

Shadow Agents

A regional director connects an AI agent to her work email. It operates for six weeks. Then a phishing email arrives. The agent drafts the wire transfer response. She approves. The wire processes.

May 23, 2026Read More
#05
GHOST

Agentic Evasion & Forensic Blindness

Ghost Agent

A malicious AI agent executes its task, exfiltrates data through an authorized channel, and self-terminates — leaving no logs, no trace, no forensic record. Normal termination is the attack.

May 18, 2026Read More
#04
Model Farming

Model Theft & IP Extraction at Scale

Model Farming

Distillation is the technique. Farming is what happens when it gets industrialized — rotating accounts, distributed infrastructure, automated pipelines running against dozens of targets simultaneously.

May 1, 2026Read More
#03
Model Distillation

Model Theft & IP Extraction

Model Distillation

You spent millions building it. I spent an API key and four months extracting it. Nobody secured what you were saying on the other side of your perimeter.

April 1, 2026Read More
#02
AI Supply Chain Attacks

AI Supply Chain · Third-Party Risk

AI Supply Chain Attacks

The model you deployed was clean. The update wasn’t.

Mar 30, 2026Read More
#01
Weaponized Trust

Prompt Injection · Social Engineering

Weaponized Trust

They Didn’t Hack You. They Read Your Job Posting.

Mar 21, 2026Read More

The Unintentional Insider

The Unintentional Insider

No attacker. No breach. Just an employee pasting proprietary data into a chatbot — and a data-loss path your controls were never built to see. The insider threat with no malice and no intrusion.

Coming Soon — Digital Content Series #10

When AI Attacks

Get the next debrief
before your board does.

New AI threat debriefs — prompt injection, agentic attacks, identity failures — the moment they publish.

Subscribe to the Series

Free  ·  No spam  ·  Unsubscribe anytime