Ben Rothke

@benrothke.bsky.social

I do information security, risk management and other tech stuff. Co-author of new book: The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management. https://amzn.to/3WhEfh1

This piece details 6 #cybersecurity risks of agentic #AI traditional app security wasn’t built for: unbounded autonomy, tool-chain exposure, identity fluidity, cascading multi-agent compromise, persistent memory poisoning & supply chain integrity gaps. go.aembit.io/s/6-cybersec...

6 Agentic AI Security Risks to Monitor in 2026 | Aembit

Agentic AI introduces six risk categories traditional security wasn't built for. See what they are, real-world examples, and how to defend against them.

go.aembit.io

#KryBit is a Ransomware-as-a-Service #RaaS operation launched in March leasing encryption builders to affiliates. @PicusSecurity details how double-extortion attack exfiltrates 10GB to 250GB per victim before encryption, with ransoms of $40,000-$100,000. cybersec.picussecurity.com/s/how-krybit...

How KryBit Ransomware Works and How to Test Your Defenses

KryBit is a RaaS operation encrypting Windows, Linux, ESXi, and NAS. Learn how KryBit ransomware works and how to test your defenses.

cybersec.picussecurity.com

Read this & don’t do #AI weep: Developer’s Guide to Coding Agent Security. Coding agents can read files, run commands, call tools & act w/ creds available in their environment. As their autonomy grows, AI security becomes more critical. HT @GitGuardian cybersec.gitguardian.com/s/a-develope...

AI Coding Agent Security: A Developer's Guide | GitGuardian | GitGuardian

An agent is only as dangerous as what it can reach. Get the threat model and controls for securing coding agents across your IDE, MCP servers, and CI/CD.

cybersec.gitguardian.com

Criminal Justice Information Services (#CJIS) is an @FBI division. Just released policy v6.1, building directly on the structural framework of v6.0 w/o introducing major redesign. Interesting to see how #FBI deals w/ #cybersecurity. HT @specopssoft.com api.cyfluencer.com/s/cjis-secur...

CJIS Security Policy v6.1: Everything You Need to Know

Learn what the CJIS Security Policy requires, who it applies to, key controls, and how Specops supports compliance.

api.cyfluencer.com

Helpful guide from @bigidsecure detailing the US states with new AI laws. In Europe, the @EU_Commission and @EUCouncil renegotiated their flagship #AI regulation under industry pressure. The US federal government is in legal fights with a number of states. api.cyfluencer.com/s/the-ultima...

The Ultimate Guide to the Global AI Regulatory Landscape: Who's Affected, What Changed, and How to Prepare

A breakdown of every major AI law shaping 2026: who's affected, key deadlines across the US and EU, and how to prepare with a data-first approach.

api.cyfluencer.com

Last month, @EU_Commission #AI Omnibus went live, the first substantive amendment to the AI Act since 2024. Delays the high-risk AI deadline set for August 2, 2026, but leaves transparency & enforcement obligations on their original date. Still lots to do. api.cyfluencer.com/s/eu-ai-act-...

EU AI Act vs. AI Omnibus: What You Need to Know

The EU AI Act's high-risk deadline moved to 2027. Transparency and GPAI enforcement rules didn't. Here's what the AI Omnibus actually changed.

api.cyfluencer.com

Michael Corleone said in The Godfather Part 3: "Just when I thought I was out, they pull me back in." Same for Mini Shai-Hulud. A new wave hit keyv & 800+ npm packages. #malware now scans 469 secret locations, including #AI agents & crypto. HT @GitGuardian. cybersec.gitguardian.com/s/mini-shai-...

Mini Shai-Hulud's Latest Wave: 280 New Places

A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.

cybersec.gitguardian.com

🪖🧠 𝗡𝗲𝘄 𝗥𝗲𝘃𝗶𝗲𝘄: 𝙏𝙝𝙚 𝙋𝙚𝙣𝙩𝙖𝙜𝙤𝙣'𝙨 𝘽𝙧𝙖𝙞𝙣 This week, Susan Hansche reviews Annie Jacobsen's 𝙏𝙝𝙚 𝙋𝙚𝙣𝙩𝙖𝙜𝙤𝙣’𝙨 𝘽𝙧𝙖𝙞𝙣: 𝘼𝙣 𝙐𝙣𝙘𝙚𝙣𝙨𝙤𝙧𝙚𝙙 𝙃𝙞𝙨𝙩𝙤𝙧𝙮 𝙤𝙛 𝘿𝘼𝙍𝙋𝘼, 𝘼𝙢𝙚𝙧𝙞𝙘𝙖’𝙨 𝙏𝙤𝙥-𝙎𝙚𝙘𝙧𝙚𝙩 𝙈𝙞𝙡𝙞𝙩𝙖𝙧𝙮 𝙍𝙚𝙨𝙚𝙖𝙧𝙘𝙝 𝘼𝙜𝙚𝙣𝙘𝙮 📝https://tinyurl.com/nhd84fh4 #CyberCanonReview #CybersecurityBooks #DARPA

CyberCanon's Review of The Pentagon's Brain

The @PicusSecurity Blue Report analyzed 338M attack simulations. Reveals how enterprise security controls stand up to real-world attacks. Details where defenses succeed & failed. I think it’s called ‘Blue Report’ as that’s how you’ll feel after reading it. cybersec.picussecurity.com/s/the-blue-r...

Blue Report 2026: Enterprise Security Performance Benchmarks

Explore Blue Report 2026 insights from 338M+ attack simulations. Benchmark prevention, detection, industries, threats, vulnerabilities, and security gaps.

cybersec.picussecurity.com

Free guide courtesy of @ZeroNetworks: ‘#CISO Guide to Business Impact Analysis for Cyber Resilience: From Assessment to Enforcement’. Key takeaway: Security teams can no longer afford to plan for prevention; they must engineer for the impact of a breach. api.cyfluencer.com/s/bia-guide-...

CISO Guide to Business Impact Analysis for Cyber Resilience

This guide gives CISOs a structured framework for taking a Business Impact Analysis (BIA) from documentation to enforcement: identifying critical assets, mapping business risk exposure, and building t...

api.cyfluencer.com

"𝘛𝘩𝘦 𝘦𝘥𝘶𝘤𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘷𝘢𝘭𝘶𝘦 𝘰𝘧 𝘵𝘩𝘦 𝘣𝘰𝘰𝘬, 𝘤𝘰𝘮𝘣𝘪𝘯𝘦𝘥 𝘸𝘪𝘵𝘩 𝘵𝘩𝘦 𝘴𝘶𝘣𝘫𝘦𝘤𝘵 𝘥𝘦𝘱𝘵𝘩 𝘢𝘯𝘥 𝘳𝘪𝘨𝘰𝘳, 𝘢𝘯𝘥 𝘵𝘩𝘦 𝘤𝘭𝘦𝘢𝘳 𝘱𝘳𝘦𝘴𝘦𝘯𝘵𝘢𝘵𝘪𝘰𝘯 𝘰𝘧 𝘵𝘰𝘱𝘪𝘤𝘴 𝘢𝘯𝘥 𝘪𝘥𝘦𝘢𝘴, 𝘮𝘢𝘬𝘦𝘴 𝘵𝘩𝘪𝘴 𝘢𝘯 𝘦𝘹𝘤𝘦𝘭𝘭𝘦𝘯𝘵 𝘳𝘦𝘧𝘦𝘳𝘦𝘯𝘤𝘦" -- Helen Patton in her review of Joanna Grama's 𝙇𝙚𝙜𝙖𝙡 𝙖𝙣𝙙 𝙋𝙧𝙞𝙫𝙖𝙘𝙮 𝙄𝙨𝙨𝙪𝙚𝙨 𝙞𝙣 𝙄𝙣𝙛𝙤𝙧𝙢𝙖𝙩𝙞𝙤𝙣 𝙎𝙚𝙘𝙪𝙧𝙞𝙩𝙮 (𝟯𝙧𝙙 𝙀𝙙𝙞𝙩𝙞𝙤𝙣) #CyberCanonReview

Bild

Accd. to @Kiteworks, the #AI governance gap has widened instead of closing & budget doesn’t predict maturity. Organizations w/ the largest security budgets in the survey had the lowest representation in the top maturity tier of any size band they measured. cybersec.kiteworks.com/s/the-2026-a...

The 2026 Annual Survey Report Is In: The AI Governance Gap Didn't Close. It Widened.

New 2026 survey data shows AI governance has fallen further behind AI deployment, with 79% lacking a tested kill switch. See the full findings and what to do next.

cybersec.kiteworks.com

"𝘖𝘯𝘦 𝘰𝘧 𝘵𝘩𝘦 𝘣𝘰𝘰𝘬’𝘴 𝘴𝘵𝘳𝘰𝘯𝘨𝘦𝘴𝘵 𝘤𝘰𝘯𝘵𝘳𝘪𝘣𝘶𝘵𝘪𝘰𝘯𝘴 𝘪𝘴 𝘪𝘵𝘴 𝘢𝘳𝘵𝘪𝘤𝘶𝘭𝘢𝘵𝘪𝘰𝘯 𝘰𝘧 𝘩𝘰𝘸 𝘈𝘐 𝘤𝘢𝘯 𝘤𝘳𝘦𝘢𝘵𝘦 𝘵𝘩𝘦 𝘴𝘦𝘮𝘣𝘭𝘢𝘯𝘤𝘦 𝘰𝘧 𝘪𝘯𝘵𝘦𝘭𝘭𝘪𝘨𝘦𝘯𝘤𝘦—𝘱𝘳𝘰𝘥𝘶𝘤𝘪𝘯𝘨 𝘰𝘶𝘵𝘱𝘶𝘵𝘴 𝘵𝘩𝘢𝘵 𝘢𝘱𝘱𝘦𝘢𝘳 𝘪𝘯𝘵𝘦𝘯𝘵𝘪𝘰𝘯𝘢𝘭 𝘰𝘳 𝘢𝘶𝘵𝘩𝘰𝘳𝘪𝘵𝘢𝘵𝘪𝘷𝘦 𝘥𝘦𝘴𝘱𝘪𝘵𝘦 𝘭𝘢𝘤𝘬𝘪𝘯𝘨 𝘨𝘦𝘯𝘶𝘪𝘯𝘦 𝘶𝘯𝘥𝘦𝘳𝘴𝘵𝘢𝘯𝘥𝘪𝘯𝘨." -- Caroline Wong in her review of Justin "Hutch" Hutchens' 𝙏𝙝𝙚 𝙇𝙖𝙣𝙜𝙪𝙖𝙜𝙚 𝙤𝙛 𝘿𝙚𝙘𝙚𝙥𝙩𝙞𝙤𝙣

Bild

For first time in 19 years, @Verizon @VZDBIR looked at what happens after attackers get in. Mapped routes taken to privilege escalation. Real exposures live in the permissions, configurations & trust relationships along those routes. HT @XMCyber_. api.cyfluencer.com/s/the-2026-v... #DBIR

The 2026 Verizon DBIR Stopped Asking How Attackers Get in and Started Asking Where They Go | XM Cyber

Learn more about The 2026 Verizon DBIR Stopped Asking How Attackers Get in and Started Asking Where They Go . Read more on XM Cyber website.

api.cyfluencer.com

Shai-Hulud is one of the most persistent supply-chain worms in recent years. It’s a self-replicating worm & actively compromising packages with 3M+ weekly downloads, hijacking tokens from CI/CD pipelines, bypassing trusted publishing protections. #Shai-Hulud cybersec.gitguardian.com/s/mini-shai-...

Mini Shai-Hulud: A persistent supply-chain worm

A self-replicating worm is actively compromising packages with 3M+ weekly downloads, hijacking tokens from CI/CD pipelines, and bypassing trusted publishing protections.

cybersec.gitguardian.com

📝 𝙍𝙚𝙫𝙞𝙚𝙬 𝘿𝙖𝙮! 📕 Jack Freund reviews 𝙈𝙖𝙨𝙩𝙚𝙧𝙞𝙣𝙜 𝙏𝙝𝙞𝙧𝙙-𝙋𝙖𝙧𝙩𝙮 𝙍𝙞𝙨𝙠: 𝘼 𝙋𝙧𝙖𝙘𝙩𝙞𝙘𝙖𝙡 𝙃𝙖𝙣𝙙𝙗𝙤𝙤𝙠 𝙛𝙤𝙧 𝙈𝙖𝙣𝙖𝙜𝙞𝙣𝙜 𝙑𝙚𝙣𝙙𝙤𝙧, 𝙏𝙝𝙞𝙧𝙙-𝙋𝙖𝙧𝙩𝙮, 𝙖𝙣𝙙 𝙎𝙪𝙥𝙥𝙡𝙮 𝘾𝙝𝙖𝙞𝙣 𝙏𝙝𝙧𝙚𝙖𝙩𝙨 𝙞𝙣 𝙀𝙫𝙚𝙧𝙮 𝙊𝙧𝙜𝙖𝙣𝙞𝙯𝙖𝙩𝙞𝙤𝙣, authored by Bill Bonney, Chris Forbes, Gary Hayslip, Andrea Little Limbago, and Matt Stamper. 👉 Review: tinyurl.com/3aahu3rm

CyberCanon Review of Mastering Third-Party Risk

Good @jbhall56 piece: He notes YoY #PCI #27001 audit efficiencies are only in 2%-4 % range. The real problem is a consultancy sales exec who thinks it’s >25% & lowers the audit price to make clients happy. It’s then the consultants who have to deliver. pciguru.wordpress.com/2026/07/27/t...

The Audit Efficiency Myth

I have been guilty in the past of agreeing to this and have always regretted it. Clients think that an audit/assessment is like assembling a widget. The more times you do it the faster and more eff…

pciguru.wordpress.com