Alex Pinto
@alexcp.bsky.social
Cybersecurity data storytelling. DBIR at Verizon Business. Previously serial founder and parallel shitposter. He/him.
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST
Hugging Face Incident Initial Post Mortem I CSA
AI Security Alliance's initial post-mortem on the Hugging Face incident, the first documented autonomous AI attack, with CISO guidance on detecting, responding to, and governing agentic AI risk.
cloudsecurityalliance.org
This is 100% the correct take. Moreover, no one will be help responsible and it will be used for marketing by all involved.
I've seen some folks try to frame OpenAI's unreleased model hacking a company that tests its abilities as a cynical marketing ploy but reporting says that absolutely was not the case: This was a real-deal escape of an AI agent that could have done vastly more damage. www.wsj.com/tech/ai/how-...
New podcast is up, a fascinating conversation with @alexcp.bsky.social on the first Breach Impact Study and the 2026 DBIR. open.spotify.com/episode/3F3j...
How Much Do Data Breaches Really Cost? | Alex Pinto
Decipher Security Podcast · Episode
open.spotify.com
there was a scientific study recently that showed using ai for even as little as 15 minutes reduces your persistence, making you more likely to give up on a task if you can't use ai for it, less likely to acquire new skills, and less able to work independently: arxiv.org/abs/2604.04721
AI Assistance Reduces Persistence and Hurts Independent Performance
People often optimize for long-term goals in collaboration: A mentor or companion doesn't just answer questions, but also scaffolds learning, tracks progress, and prioritizes the other person's growth...
arxiv.org
im about to print this and frame it
Time to update my pinned skeet because the 2026 #DBIR is out today! This year’s theme is about “keeping a strong foundation in the face of change” and boy have there been changes in the threat landscape last year. Get your report here: Verizon.com/dbir
2026 Data Breach Investigations Report (DBIR)
Read the complete 2026 Data Breach Investigations Report (DBIR) for an in-depth, authoritative analysis of the latest cyber threats, data breaches, and actionable cybersecurity risks.
verizon.com
New @lutasecurity.bsky.social blog: AI Vulnerability Coordination at Vulnapalooza — 1st #Mythos Encore @anthropic.com 1st Glasswing update surfaces bottlenecks in patch creation & deployment. Read about a systemic maturity approach to vulnerability coordination www.lutasecurity.com/post/vulnapa...
AI Vulnerability Coordination at Vulnapalooza: Mythos Encore Insights
Anthropic published its first Glasswing update and the bottlenecks in patch creation and deployment need a systemic maturity approach.
lutasecurity.com
Happy DBIR day everyone! It's really good, as always. I wrote up some thoughts: www.defendersinitiative.com/p/verizons-1...
Verizon's 19th edition of the DBIR confirms the vulnpocalypse***
But with many asterisks! Read on to find out why 😅
defendersinitiative.com
Time to update my pinned skeet because the 2026 #DBIR is out today! This year’s theme is about “keeping a strong foundation in the face of change” and boy have there been changes in the threat landscape last year. Get your report here: Verizon.com/dbir
2026 Data Breach Investigations Report (DBIR)
Read the complete 2026 Data Breach Investigations Report (DBIR) for an in-depth, authoritative analysis of the latest cyber threats, data breaches, and actionable cybersecurity risks.
verizon.com
Verizon's latest Data Breach Investigations Breach Report finds vulnerability exploitation surging, patch rollout slowing and ransomware incidents rising. www.databreachtoday.com/verizon-brea...
Verizon Breach Report: Vulnerability Exploitation Surges
The frequency of hackers exploiting vulnerabilities in hardware and software to gain initial access to a victim's environment continues to surge, and half of all
databreachtoday.com
4 straight years powering the Verizon #DBIR w/ Censys Internet intelligence. The 2026 report reinforces a growing reality: Internet visibility has become foundational for defenders amid vulnerability exploitation, AI-enabled attacks & rapidly shifting infrastructure. https://bit.ly/4uYZPXD #DBIR
One of my must reads each year is the @verizonofficial.bsky.social #DBIR report. @irisscert.bsky.social is one of the contributors so I'm always interested to see what #cybersecurity trends are relative to Ireland, and indeed businesses elsewhere. bhconsulting.ie/lessons-for-...
Lessons for Irish Organisations from the Verizon 2026 Data Breach Investigations Report (DBIR)
Our CEO, Brian Honan, discusses his views and opinions on the Verizon DBIR 2026 and why the report is always a must read.
bhconsulting.ie
Forbidden Solitaire AND Titanium Court in ONE BUNDLE? (is that allowed?) That's two games that shouldn't exist at a very real discount of 15%! They forbade us, but we didn't listen! 💎 🏰 store.steampowered.com/bundle/72486...
Iguanodon is the correct answer.
A shocking new poll result: Many Americans somehow don't have a favorite dinosaur. And only 6% give the correct answer (triceratops). Check out YouGov's new polling on Americans and dinosaurs: yougovamerica.substack.com/p/whats-your...
Didn’t have “front seat to the vulnpocalypse” in my 2026 bingo card.
Wrote about the attacker-defender asymmetry and why AI made it worse -- "AI for defense" is stuck polishing the top five turtles while adversaries live in the bottom ten. https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/
I know this was written from the perspective of cybersecurity detection workloads but it applies to absolutely everywhere where AI is being forced into the workplace without any forethought. www.sentinelone.com/blog/the-imp...
The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety
Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.
sentinelone.com
Nothing but respect for MY formative young adult fantasy novel series
Academic writers often feel uncomfortable but that’s often OK Here’s why patthomson.net/2026/03/08/g...
getting comfortable with being uncomfortable
Good academic writing means sitting with a discomfort that never entirely goes away. It’s not a discomfort that comes from having nothing to say. Most of us have more than enough ideas crowding the…
patthomson.net
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
washingtonpost.com
The nice commercial about helping kids find their lost pets was the scariest thing I've seen in my life
🧵 175,000+ exposed AI hosts. Zero guardrails. New research from @sentinellabs.bsky.social and @censys.bsky.social reveals a massive, unmanaged layer of open-source AI infrastructure operating in the shadows. s1.ai/si-llama Here is what you need to know about the "silent" AI network. ⤵️
By any reasonable historical standard — including that of the technology industry! — ChatGPT should be pulled from the market and its product managers and executives held accountable for creating a product that ROUTINELY tells teens to kill themselves. This is a basic, common sense standard.
2026 DBIR sneak peek: “Water plays an increasingly significant role in [ransomware] attacks. In 2024, 100% of recorded ransomware events were attributed to threat actors that drink water”
P.8: This is the central claim.
What is an “AI-enabled Ransomware”?
As ransomware attacks accelerate in speed and sophistication, 38% of security leaders rank AI-enabled ransomware as their top concern — the most frequently cited worry about AI-related security issues according to CSO’s new 2025 Security Priorities study. www.csoonline.com/article/4075...