When AI burst upon the scene a few years ago, it became a boon to the cybersecurity industry. The AI sector pushed a narrative that AI was not just a tool, but a way to replace human workers. Cyber threats exploded and there was greater demand for tools and services. The security industry glommed onto that narrative with AI-driven services. That had the expected result of destroying any goodwill available to AI technology.
However, recent revelations about the effectiveness of AI replacements are making proponents change their tune. What changed? Let’s start with human fertility.
Not all scams take money from you. One of the biggest security scams is the belief that once you have joined a Meta platform, it is impossible to leave. The news the Meta is working with a government contractor to make facial recognition tech for ICE agents has accelerated interest in how to escape Meta Hell. The question is, how?
Migration from Meta platforms is no longer a niche trend. Through 2025 and 2026 there is a sustained structural shift in the social media. Just consider the explosive growth of Bluesky, which closed 2025 with over 41.4 million registered users, a 60% year-over-year increase, with daily active users climbing past 4.5 million. That represents real growth from status into mainstream viability.
Collaboration tools have fueled configuration drift facilitating phishing attacks since they became widespread during the COVID pandemic. The core of the problem is, as usual, human failure, or more accurately, human procrastination.
Configuration drift happens when vendors and customers join corporate networks with supposedly temporary credentials. When those credentials are not revoked quickly after the collaboration, system settings gradually, almost imperceptibly, diverge from a secure baseline state.
Collaboration tools, beginning with email in the 1970s, were largely clunky, on premises and limited to technically sophisticated organizations. Through the 20 years following the turn of the century they became more sophisticated and allowed inclusion of users outside the networks, like vendors, consultants, and customers. Approximately 400 to 600 million people in professional contexts today use Microsoft Teams, Slack, Google Workspace, Zoom, and dozens of others collaboration tools. Gartner said 90% of Fortune 500 companies standardize on Teams. Moreover, every team that uses collaboration tools configures every collaboration tool differently with no central enforcement.
“Configuration drift is one of the most under-recognized risks in modern cybersecurity,” said Garrett Hamilton, CEO and founder of Reach Security. “Security tools are constantly changing due to updates, new features, and operational adjustments. Over time, those changes create drift that quietly weakens defenses. Organizations need a continuous way to validate that the controls they depend on are still working as intended.”
Cybersecurity Upside Down is a self-published book about the benefits of content disarm and reconstruction (CDR) security services and tools. Written by Benny Czarny, the CEO of OPSWAT, a respected provider of CDR, it is an attractive coffee table book to place in office reception rooms. It provides a good argument for adoption of CDR in large enterprises and government networks.
It is also about 150 pages too long, repeats the same argument several times, and has copious sections written by AI. There are also a lot of graphics (about 50 pages worth) that are also AI generated and not always illustrating the text. All of that tends to obfuscate the good argument Czarny makes.
The data broker market is worth half a trillion dollars and growing at a rate of 7.3 percent annually through 2033. That means they don’t care that you want your privacy. They are making too much money selling your personal information to care. That lack of concern doesn’t just affect an individual’s privacy. It threatens their security and that of nation states. The personal data removal and online privacy niche is fixing the problem. That industry, however is worth a 10th of the data broker market so it doesn’t have the political clout of data brokers. And nowhere is it bigger than the healthcare industry, according to Rob Shavell, CEO of Deleteme.
A public relations firm in the United Kingdom said the quiet part out loud about cybersecurity marketing: that much of it is fiction if not outright fraudulent.
Whiteoaks International surveyed 152 senior marketing, PR and communications professionals in the country, working in cybersecurity. The results found 30% said they helped produce content that was excessive, misleading, or unsubstantiated. More than half (51%) said they had seen this type of messaging in the sector.
Many shady practices on the internet are scams, but some seem "scammy." Cyber Protection Magazine came across one such operation.
While ordering food on Grubhub recently, a pop-up appeared telling us we “earned a reward!” Clicking on the link it offered a $20 rebate on my next purchase. Sounds good, doesn’t it? Not really.
Note: All the companies involved in this transaction will be named in this article. All were contacted for comment. Only Grubhub responded with a request for additional information and then went silent.
Even though the transaction was occurring within the Grubhub mobile app, the pop-up was from an organization called Cashback-Now. The company name is relatively common for several companies, all apparently running the same type of business. In this case the URL is cashback-now.com.
Time to dig into the RSAC Conference notes. It was only three years ago that vendors were warning of Q-day, the day quantum computers could break current encryption, filled the pages of technology publications and even general news outlets. Those warnings are much more muted this year. What happened?
Primarily, the work of NIST solved the issue in setting new standards for encryption. All the post-quantum computing companies, like PQShield and SandboxAQ, are offering encryption products that are more alike than they are different and all are doing good business providing tools and services. We seem to be more than ready for the dreaded Q-Day.
Then, again, the progress on creating an encryption-breaking quantum computer is maddeningly slow. The industry still insists 2029 is the Q day ETA, and it will break military-grade encryption in one week… on a single document. Assuming a nation state that has such a computer has stolen 20,000 encrypted documents, it would take 38 years to decrypt them all. But the number of stolen encrypted documents, although inestimable, is probably orders of magnitude higher. So reality mutes the projections of potential disaster.
Premium Membership Required
You must be a Premium member to access this content.
Anthropic’s announcement of Mythos threw a lot of FUD into the cybersecurity market without significant third-party validation of its abilities. Is that FUD justified, another legal form of extortion designed to get security budget dollars, or just another weird marketing ploy? Maybe more to the point, is it a sheep in wolf’s clothing?
Mythos does not address encryption, identity or social engineering, representing most of the issues of cybersecurity, It just deals with vulnerabilities in code development. That might negatively impact the cloud-native application protection platform (CNAPP) sector but, at the same time, the tool is only being offered to Fortune 100 companies. Meanwhile, there are hundreds of thousands of large, medium and small enterprises that won’t get it, at least anytime soon unless they steal it.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.