The Web Is Mostly Bots Now
51% of web traffic is automated. AI scrapers visit five times per page. CAPTCHA is dead. Cloudflare traps bots in AI-generated mazes. The web we built for humans is being renegotiated.
Passive DNS Is the Log You Are Not Collecting
I added passive DNS logging to my network and found a compromised IoT device within 48 hours. Most organizations have no idea what their DNS traffic reveals.
Lexis1234
LexisNexis got breached through an unpatched React Server Components vulnerability. The RDS master password was allegedly Lexis1234. Federal judge accounts were in the leak.
The CVE System Is Breaking and Nobody Has a Backup Plan
The NVD backlog hit 18,000 unanalyzed CVEs in 2025. MITRE's funding was nearly cut. I now cross-reference four sources because trusting CVE alone will get you breached.
7,500 Building Controllers and a Vendor Who Will Not Patch
A researcher found 7,500 internet-exposed Honeywell IQ4 building controllers. 20% are accessible without authentication. Honeywell says it is not their problem.