The Docket: Dutch Intelligence Says China's Cyber Parity Is a Detection Problem Dutch intelligence says China's offensive cyber capability now stands near U.S. levels, but the harder warning is how much activity defenders still miss.
Explain This: LMDeploy Turned an Image Fetch Into an Internal Network Probe LMDeploy's SSRF bug shows how a model server feature can become a fast path into cloud metadata and internal services.
Exhibit A(I): Your 2026 HIPAA Plan Needs Evidence, Not Another Awareness Ritual The useful lesson in the latest HIPAA webinar push is simple: compliance only changes outcomes when teams convert awareness into evidence.
Policy Roast: Your Hospital Ransomware Policy Is Not a Policy if Scope Comes After Recovery If a hospital declares normal operations before it knows whose data was exposed, the cyber policy is managing optics, not risk.
Policy Roast: Your AI Security Source Policy Is Not a Policy if It Cannot Route Action If your AI security intake has no owner, no escalation rule, and no decision field, it is not a policy. It is just anxious scrolling.
Explain This: NIST Just Turned the NVD Into a Triage System The public data layer underneath the whole vulnerability ecosystem is shifting from completeness to triage. That changes how operators should read CVSS, KEV, VPR, EPSS, policy, and patch SLAs.
The Docket: The SEC's CAT Review Is Really About Privacy, Security, and Market Surveillance The SEC's CAT review turns market infrastructure into a governance fight over privacy, surveillance scale, retention, and security.