DoD paused CMMC Phase II third-party audits for self-attestation. Zero trust's still right — but we just watched self-reporting fail in federal healthcare fraud. Who watches the watchers?
securityboulevard.com/2026/0…
"Air-gapped" isn't a defense — it's an assumption. TrojPix turns an HDMI cable into a covert radio transmitter, exfiltrating data at 8.1 Mbps with zero network footprint. Your EDR, DLP, and SIEM never see it leave. The only lever left: Zero Trust.
My analysis:
securityboulevard.com/2026/0…
100% GPU utilization. 60% of cycles wasted on recomputation. @Solidigm and @MinIO showed at #AIIFD5 why that's an architecture problem — and what the fix actually looks like.
paradigmtechnica.com/2026/07…
Recovery and trustworthiness aren't the same thing. @Commvault made that distinction the centerpiece of their #AIIFD5 presentation — and it reframes how enterprises should think about AI resilience entirely.
paradigmtechnica.com/2026/07…
The file system isn't passive infrastructure anymore. @CTERA made that case precisely at #AIIFD5 — and the argument lands hard for anyone deploying agents at scale.
paradigmtechnica.com/2026/06…
5–10% GPU utilization. The model's fine. The storage layer is the problem. @Scality's ADI presentation at #AIIFD5 was a precise systems-level diagnosis of enterprise AI's real bottleneck.
paradigmtechnica.com/2026/06…
Vuln exploitation just overtook credential abuse in the 2026 DBIR. So the password is dead?
86,000 cracked Fortinet credentials in FortiBleed say otherwise—no zero-day needed.
A ranking change isn't a risk change. My case for going passwordless:
securityboulevard.com/2026/0…
Govts worldwide are catching a bad case of VC envy—and Sen. Sanders just made it policy. Seizing 50% of AI companies wouldn't democratize AI. It would lobotomize it. Government's job is to build the conditions for business to thrive, not to confiscate the upside. wp.me/p91vu9-8OYo
NIST just advanced 9 candidates to Round 3 of its additional PQC digital signatures process. Four mathematical families. Two-year timeline. And a hard lesson from SIKE and Rainbow: cryptographic monoculture is a systemic risk.
My analysis on Security Boulevard:
securityboulevard.com/2026/0…
Before your next PAM or IGA investment, do you actually know what you're protecting? @SPHERETechSol is building the identity hygiene layer the industry has been missing.
My RSAC 2026 Vendor Spotlight: paradigmtechnica.com/2026/05…
The U.S. just committed $2B to quantum computing via the CHIPS Act — and took equity stakes in all 9 recipients. @IBM, D-Wave, Rigetti, Quantinuum & more. Shor's algorithm started a clock. Washington is racing to answer it.
securityboulevard.com/2026/0…
The unsolved problem in container security isn't detection — it's the 80-day gap between a published fix and when your engineers can use it. My RSAC Vendor Spotlight on Echo.AIparadigmtechnica.com/2026/05…#DevSecOps#RSAC2026
AI coding agents are pulling open source packages faster than any developer can audit them. @ActiveState is building the answer — a curated, hermetically sealed catalog of verified components.
My RSAC 2026 Vendor Spotlight: paradigmtechnica.com/2026/05…
92% of security teams are confident in detection. 70% still have vulns hitting production. The gap isn't the scanner — it's everything after. My RSAC Vendor Spotlight on @code_armor and why the control plane wins. paradigmtechnica.com/2026/05…