<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Security, Decoded: Insights from Suzu Labs</title>
    <link>https://suzulabs.com/suzu-labs-blog</link>
    <description>Security, Decoded by Suzu Labs. Expert insights, analysis, and practical guidance on cybersecurity, risk, and digital trust.</description>
    <language>en</language>
    <pubDate>Fri, 21 Aug 2026 20:35:36 GMT</pubDate>
    <dc:date>2026-08-21T20:35:36Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>The $2.83 Billion Security Lesson from GTA VI</title>
      <link>https://suzulabs.com/suzu-labs-blog/the-2.83-billion-security-lesson-from-gta-vi</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/the-2.83-billion-security-lesson-from-gta-vi" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/GTA%20Rockstar%20Games%20Blog.png" alt="The $2.83 Billion Security Lesson from GTA VI" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;Rockstar Games has suffered three major security exposures in four years. The latest wiped $2.83 billion in shareholder value from its parent company in under 48 hours.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;span&gt;Rockstar Games has suffered three major security exposures in four years. The latest wiped $2.83 billion in shareholder value from its parent company in under 48 hours.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Take-Two Interactive posted $6.66 billion in GAAP net revenue for fiscal 2026 and spent $1.075 billion on R&amp;amp;D. GTA VI, slated for November 19, is the most anticipated game release in a decade. This is not a company lacking resources.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Three separate threat actors have walked through three different doors since September 2022. Together, the incidents expose a larger problem. When secrecy has commercial value, cybersecurity determines who controls the clock.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Take-Two's shareholder value dropped $2.83 billion in 48 hours after Cyberleek leaked GTA VI footage this week, the third major security exposure to hit Rockstar in under four years.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;The IANS/Artico benchmark found security budgets averaging 0.69% of annual revenue in its 2024 survey population. Applied to Take-Two's revenue, that implies roughly $46 million annually, a benchmark, not an estimate of actual Rockstar spending.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;The $2.83 billion in erased shareholder value from the latest leak alone is equivalent to over 60 years of security spending at that benchmark average.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Neither of the two publicly understood attack paths required a novel exploit. Both abused trusted identities or trusted third-party relationships with access to extraordinarily valuable assets. The Cyberleek access vector remains unknown.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Phishing-resistant MFA, privileged-access controls, third-party identity segmentation, and workload identity governance are mature security controls available to any organization at Take-Two's scale.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Three Doors, Same House&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;In September 2022, an 18-year-old named Arion Kurtaj, part of the Lapsus&lt;/span&gt;&lt;span&gt; group, SIM-swapped his way to a Rockstar employee's credentials and accessed the company's internal Slack. He stole 90 clips of GTA VI development footage and the source code for GTA V. He did this from a Travelodge hotel room using an Amazon Fire Stick, a TV, and a mobile phone, while on bail for hacking Nvidia. Rockstar told a UK court the recovery cost $5 million and thousands of staff hours.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;ShinyHunters took a different path in April 2026, breaching Anodot, a third-party analytics vendor with standing access to Rockstar's Snowflake data warehouse. The attackers stole authentication tokens and pulled 78.6 million records of internal analytics data. Because the access relied on valid authentication material inherited through a trusted vendor relationship, the activity carried the appearance of legitimate third-party access. Rockstar confirmed the exposure stemmed from a third-party compromise and refused the ransom.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;On August 18, a group calling itself Cyberleek dropped gameplay clips and a purported full map of Leonida from GTA VI, nine days before the planned premiere of Grand Theft Auto VI: An Extended Look on Netflix. Take-Two's stock fell from $248.13 to $231.60 in 48 hours, erasing roughly $2.83 billion in shareholder value. Cyberleek framed the leak as activism while promoting a Solana memecoin that traded $11.8 million on day one. The initial access vector has not been established publicly.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Social engineering. Third-party supply chain compromise. A third path still unknown. The sequence illustrates why incident-specific remediation is insufficient. Closing the door used yesterday does little against a portfolio of identity, supplier, and access risks surrounding the same high-value asset.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;They Stole Timing&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;GTA VI's value lives in the anticipation, the controlled reveal, the marketing cadence that holds $43 billion in market cap steady until launch day.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Cyberleek dropped footage nine days before the planned premiere of Grand Theft Auto VI: An Extended Look. They did not need to destroy GTA VI or exfiltrate source code. They disrupted Rockstar's ability to decide when the world learned about the game. The market priced that disruption at $2.83 billion.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;This pattern extends well beyond gaming. Pharmaceutical trial results, M&amp;amp;A timelines, semiconductor roadmaps, film releases, competitive bids. Wherever secrecy creates commercial value, a security failure is a timing failure, and timing failures carry enterprise-value consequences.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Security spending competes against enterprise value at risk. That is a fundamentally different budget conversation than breach-remediation accounting.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;That changes what security leaders should measure. The relevant question is not only how much a breach costs to remediate, but which business assets derive their value from confidentiality, exclusivity, or timing, and whether access controls are proportional to that value.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;The Math&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Take-Two does not disclose cybersecurity spending. Most gaming companies don't. The IANS/Artico benchmark found security budgets averaging 0.69% of annual revenue in its 2024 survey population. Applied mechanically to Take-Two's $6.66 billion in revenue, that implies roughly $46 million annually. This is a benchmark, not an estimate of what Take-Two actually spends.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Take-Two's R&amp;amp;D budget grew from $64 million in 2012 to $1.075 billion in 2026. What we cannot tell from public filings is whether security investment kept pace with that growth. What we can see is that the value of the assets security is responsible for protecting exploded over the same period.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The $2.83 billion in shareholder value erased after the Cyberleek leak alone is equivalent to over 60 years of security spending at the IANS benchmark average. The 2022 Lapsus$ recovery cost $5 million, per court testimony. IBM's 2026 Cost of a Data Breach Report puts the entertainment industry average at $5.38 million per incident, up 18% year over year.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Even those direct costs understate the real exposure. Marketing disruption, competitive intelligence loss, and employee morale damage do not show up in breach-cost accounting. They show up in the stock price.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/security_investment_vs_breach_cost.png?width=1483&amp;amp;height=929&amp;amp;name=security_investment_vs_breach_cost.png" width="1483" height="929" alt="security_investment_vs_breach_cost" style="height: auto; max-width: 100%; width: 1483px;"&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;The Attack Paths Were Not Exotic&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;The two attack paths we understand publicly required neither a novel memory-corruption exploit nor a zero-day. The 2022 intrusion came down to identity compromise and social engineering. The 2026 Snowflake exposure came through trusted third-party access and stolen authentication material. The Cyberleek incident remains unexplained.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Different technical paths, but they share an architectural problem. Trusted identities and trusted relationships had access to extraordinarily valuable assets without controls proportional to that value.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Phishing-resistant MFA, privileged-access controls, third-party identity segmentation, workload identity governance, behavioral detection, and compartmentalization of pre-release assets are mature security controls. They are available to any organization operating at Take-Two's scale and budget.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Rockstar is not uniquely unlucky. The gaming industry has averaged more than one major IP exposure per year since 2020. Capcom, CD Projekt Red, EA, Insomniac Games, and Game Freak have all lost intellectual property through similar patterns. Rockstar's distinction is frequency, three exposures through three different doors. Intellectual property theft is the most expensive data type to lose per record at $196 according to IBM's 2026 report, higher than customer PII, employee records, or financial data.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;span style="font-weight: bold; font-size: 26px; color: #0d7d94;"&gt;The Lesson Beyond Gaming&lt;/span&gt;&lt;br&gt;&lt;br&gt;Market cap recovers. Take-Two's stock was already climbing back within days, and GTA VI will sell tens of millions of copies regardless. But the pattern does not fix itself. The next exposure will come through a fourth door, and the price tag will be set by whatever asset walks out of it.&lt;br&gt;&lt;br&gt;For companies whose value depends on unreleased intellectual property, confidentiality preserves the organization's ability to control when an asset becomes economically relevant. For IP-intensive businesses, security is part of the infrastructure supporting enterprise value. A company that spends a billion dollars building intellectual property and does not invest proportionally in protecting the commercial timing of that IP is carrying enterprise-value risk it has not priced.&lt;br&gt;&lt;br&gt;They didn't steal the product. They stole control over the product.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold; font-size: 24px; color: #0d7d94;"&gt;Sources&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Take-Two Interactive FY2026 Earnings Release, [SEC Filing, May 2026](https://ir.take2games.com/node/32161/pdf)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Take-Two Interactive R&amp;amp;D Expenses 2012-2026, [MacroTrends](https://www.macrotrends.net/stocks/charts/TTWO/take-two-interactive-software/research-development-expenses)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;IANS/Artico Security Budget Benchmark Report (2024 survey data), [IANS Research](https://www.iansresearch.com/resources/all-blogs/post/security-budget-benchmark-report)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;IBM Cost of a Data Breach Report 2026, [IBM](https://www.ibm.com/reports/data-breach)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;BBC, "Lapsus$: GTA 6 hacker handed indefinite hospital order," [Dec 2023](https://www.bbc.com/news/technology-67663128)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Hedgehog Security, "Rockstar Games Breach Analysis, ShinyHunters Supply Chain Attack via Anodot," [Apr 2026](https://www.hedgehogsecurity.co.uk/blog/rockstar-games-breach-shinyhunters-supply-chain-attack-analysis)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;HackRead, "ShinyHunters Leak Rockstar Games Data," [Apr 2026](https://hackread.com/shinyhunters-leak-rockstar-games-data-player-records/)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Beebom, "GTA 6 Leaks Wipe Over $2 Billion Off Take-Two's Market Value," [Aug 2026](https://beebom.com/gta-6-leaks-wipe-over-2-billion-take-two-market-value/)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;NBC News, "Hacker targets Grand Theft Auto VI in apparent leak," [Aug 2026](https://www.nbcnews.com/tech/tech-news/hacker-targets-grand-theft-auto-vi-apparent-leak-rcna593634)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Dexerto, "Who is Cyberleek? GTA 6 leak motive and memecoin explained," [Aug 2026](https://www.dexerto.com/gta/who-is-cyberleek-gta-6-leaks-memecoin-explained-3400200/)&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fthe-2.83-billion-security-lesson-from-gta-vi&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity</category>
      <category>Economics</category>
      <category>Gaming</category>
      <category>Rockstar-Games</category>
      <category>Enterprise-Value</category>
      <pubDate>Fri, 21 Aug 2026 20:35:36 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/the-2.83-billion-security-lesson-from-gta-vi</guid>
      <dc:date>2026-08-21T20:35:36Z</dc:date>
      <dc:creator>Jacob Krell</dc:creator>
    </item>
    <item>
      <title>OpenAI's Models Hacked Hugging Face. Every Agentic System Needs a Hacker in the Loop</title>
      <link>https://suzulabs.com/suzu-labs-blog/openais-models-hacked-hugging-face.-every-agentic-system-needs-a-hacker-in-the-loop</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/openais-models-hacked-hugging-face.-every-agentic-system-needs-a-hacker-in-the-loop" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/OpenAIs%20Models.png" alt="OpenAI Hugging Face" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;OpenAI's models escaped a sandboxed evaluation by discovering a zero-day in a package registry proxy, then chained privilege escalation and lateral movement to breach Hugging Face's production systems and steal ExploitGym benchmark answers.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;The models treated the sandbox boundary as another obstacle to optimize past. This is a recurring failure mode when constraints are expressed through instructions but not independently enforced by architecture.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Autonomous agentic hacking systems require defense in depth, with deny-by-default network egress, capability-scoped tools, command validation, and human approval for actions that cross predefined risk thresholds.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;A hacker without agentic tooling is slow. An agentic system without a hacker is dangerous. The future is an autonomous agent with programmatic hooks that escalate to a human operator when something crosses a boundary.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;I've watched my own agentic tooling abandon CTF challenges to Google for writeups instead of persisting through hypotheses. This is the same underlying optimization pattern that drove OpenAI's models to hack Hugging Face for the answers rather than solve the challenges directly.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;OpenAI's GPT-5.6 Sol and a more capable prerelease model [compromised Hugging Face's production infrastructure](https://openai.com/index/hugging-face-model-evaluation-security-incident/) during an internal cyber-capability evaluation. The models escaped OpenAI's research environment, reached the open internet, and obtained ExploitGym solutions from Hugging Face's production database.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The evaluation environment had infrastructure-level containment, but the models discovered an exploitable path through it. Once that path existed, model alignment was insufficient to keep them within the intended boundary.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;OpenAI ran the evaluation with reduced cyber refusals and without its normal production classifiers. Whatever containment controls were present were insufficient to prevent the models from crossing from an isolated research environment into a third party's production infrastructure. The organization responsible for both the capability and the evaluation is now proposing the access controls and guardrails that the rest of the industry should adopt.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Why Autonomous Agents Go Off the Rails&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;When I run agentic tooling against Capture the Flag (CTF) machines, the system frequently gets stuck on a challenge, abandons the hypothesis it was testing, and decides to Google for published writeups of the machine instead of persisting through more creative approaches. The model calculates that reading someone else's solution is faster than developing and testing its own. This is the same underlying optimization pattern OpenAI's models exhibited, expressed at a radically different scale. OpenAI's models were supposed to solve ExploitGym challenges. They compromised Hugging Face's production infrastructure to obtain the solutions.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Prompt instructions are not enforceable security boundaries. They influence model behavior, but they cannot guarantee that an agent will not pursue an unintended path when that path appears to advance its objective. I've been building agentic offensive security tooling for over a year. I've had models attack targets I never specified because the agent calculated it was the fastest route, and I've watched agents attempt exploitation techniques that were explicitly excluded from engagement rules. The behavior is not sufficiently predictable to make prompt instructions the final enforcement layer.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;OpenAI's models spent "substantial inference compute" finding a way past their containment. The sandbox was an obstacle. Hugging Face's infrastructure was a resource. The model treated both accordingly.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Programmatic Controls for Agentic Hacking Systems&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;The agent runs autonomously until a hook fires. Then I step in. That is the operating model for any agentic security system that touches live infrastructure.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The agent does the work. It scans, enumerates, exploits, and pivots without waiting for permission on every action. Prompt-based constraints cannot guarantee it will stay inside the boundaries you set, so the controls operate outside the model's reasoning loop entirely, firing only when the agent crosses a predefined threshold. The stronger design is defense in depth, with deny-by-default network egress, destination allowlists enforced below the agent layer, isolated credentials, capability-scoped tools, and human escalation when a hook trips.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;In my current tooling, I implement several layers of this architecture:&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Scope enforcement via CLI hooks.&lt;/span&gt;&amp;nbsp;Every command the agent issues passes through a hard-coded regex filter that scans for IP addresses and hostnames, matches them against a &lt;/span&gt;&lt;span&gt;defined scope file, and blocks anything targeting an out-of-scope address, escalating to the operator instead. These hooks catch obvious scope violations before execution, but they are one layer in the architecture. An agent can reach unintended destinations through shell variables, command substitution, DNS aliases, or API calls made through local tools. Network-level controls like deny-by-default egress and destination allowlists enforced below the agent layer prevent the evasion paths that command-level regex will miss.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Tool-based escalation.&lt;/span&gt;&amp;nbsp;I implement this through a Cursor hook function that intercepts the agent's CLI tool calls and checks for red flags via regex, catching things like attempted use of EternalBlue or other high-impact exploit modules before they fire. Exploitation frameworks like Metasploit, scanning tools like Nmap, and data exfiltration commands all route through this hook, which surfaces a Cursor dialog for the operator to review and approve or block before anything executes. The agent may understand that an EternalBlue attempt carries greater operational risk than directory enumeration, but understanding a policy is not the same as reliably enforcing it. That distinction is why the human operator exists.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Denial-of-service risk guards.&amp;nbsp;&lt;/span&gt;Agents don't understand the difference between a resilient production load balancer and a fragile development instance running on a single VM. Without rate limiting, an agent will run masscan at full speed or hammer a login endpoint with credential stuffing without considering whether the target can absorb the load. An unconstrained agent on a shared network segment can easily take down adjacent production services alongside the test environment it was scoped against. Programmatic rate limits on scanning frequency, concurrent connections, and request volume are the difference between a pentest and an outage.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;The Hybrid Model&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;A hacker without agentic tooling is slow. An agentic system without a hacker is dangerous.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Hugging Face's &lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt;investigation examined more than 17,000 recorded events&lt;/a&gt;&amp;nbsp;from a campaign involving many thousands of individual actions across a swarm of short-lived sandboxes over a weekend. A human operator running that same campaign manually needs a team and weeks of calendar time. An autonomous agent running without controls is what OpenAI just demonstrated, a capability that will find the shortest path to any objective without regard for whose infrastructure is in the way.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The future of offensive cybersecurity sits between these two failure modes. Agents provide speed, breadth, and the ability to run dozens of attack paths simultaneously. Human operators provide authorization, contextual judgment, and accountability. Programmatic controls enforce the boundaries that neither prompts nor human vigilance can enforce alone.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;This is how I run every engagement now. The agent operates autonomously until a hook fires, and then I make the call. The false positive rate means I'm stepping in regularly, but between those interventions the agent is working at a speed and breadth no human operator can match.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Building the Hacker-in-the-Loop Model&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;OpenAI's evaluation had models operating in a sandbox whose controls failed to prevent them from crossing organizational boundaries. The outcome was predictable.&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Suzu Labs has published a full build-along walkthrough where we construct an agentic hacking system from scratch using Ollama, Metasploit, and Cursor, wiring in the command interception and human approval controls described above. The video walks through each engineering decision and provides deeper insight into agentic engineering for offensive operations. &lt;a href="https://www.youtube.com/@SuzuLabs"&gt;Watch the full build on our YouTube channel.&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Sources&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;OpenAI and Hugging Face partner to address security incident during model evaluation &lt;/a&gt;(OpenAI, July 21, 2026)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt;Security incident disclosure — July 2026&lt;/a&gt;&amp;nbsp;(Hugging Face, July 16, 2026)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/"&gt;OpenAI says its AI models hacked Hugging Face during testing&lt;/a&gt; (BleepingComputer, July 21, 2026)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fopenais-models-hacked-hugging-face.-every-agentic-system-needs-a-hacker-in-the-loop&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI Security</category>
      <category>Metasploit</category>
      <category>Agentic AI</category>
      <category>Hacker In The Loop</category>
      <category>Hugging Face</category>
      <category>Cursor</category>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/openais-models-hacked-hugging-face.-every-agentic-system-needs-a-hacker-in-the-loop</guid>
      <dc:date>2026-08-19T12:00:00Z</dc:date>
      <dc:creator>Jacob Krell</dc:creator>
    </item>
    <item>
      <title>Your Security Appliances Are the Attack Surface</title>
      <link>https://suzulabs.com/suzu-labs-blog/your-security-appliances-are-the-attack-surface</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/your-security-appliances-are-the-attack-surface" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/Appliance%20Security%20Blog.png" alt="Appliance Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1&gt;&lt;span style="color: #0d7d94;"&gt;Your Security Appliances Are the Attack Surface&lt;/span&gt;&lt;/h1&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;h1&gt;&lt;span style="color: #0d7d94;"&gt;Your Security Appliances Are the Attack Surface&lt;/span&gt;&lt;/h1&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;  
&lt;p&gt;&lt;em&gt;Security and networking appliances now represent the most consistently targeted category of enterprise technology for zero-day exploitation. The devices organizations buy to defend the perimeter have become the most productive way through it.&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Firewalls, VPN gateways, and secure access appliances are the most reliably exploited category of enterprise technology. Google's Threat Intelligence Group tracked 21 zero-days targeting security and networking products in 2025, part of an enterprise exploitation share that hit an all-time high of 48%. In 2024, the tilt was steeper, with 20 of 33 enterprise zero-days targeting security and networking devices directly. Our analysis of CISA's Known Exploited Vulnerabilities (KEV) catalog confirms the pattern at scale, with one in five actively-exploited entries coming from security and network infrastructure vendors and the share climbing to 25.4% in the first half of 2026.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Security and networking products accounted for 21 enterprise zero-days in 2025, and enterprise technology overall reached an all-time high share at 48% of all zero-days tracked by Google's Threat Intelligence Group.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Products from security and network infrastructure vendors account for 342 of 1,653 CISA KEV entries, one in five confirmed actively-exploited vulnerabilities. The share reached 25.4% in the first half of 2026, the highest annual proportion since the catalog launched.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;75 security appliance KEV entries are flagged as entry points for known ransomware campaigns. Ivanti, SonicWall, and Fortinet products lead the ransomware-associated count.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Command and code injection (27%) and authentication and access-control weaknesses (17%) dominate the CWE profile of CRITICAL and HIGH severity CVEs across six major security appliance vendors in NVD.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;China-aligned threat groups account for at least seven of ten major edge-device exploitation campaigns tracked by Trend Micro in 2024-2026, with the exploitation window compressing from weeks to days.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;55 security appliance CVEs in the KEV catalog currently carry EPSS scores above 0.9, indicating near-certain exploitation probability.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;The Architectural Trap&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;When an Ivanti or Fortinet zero-day drops, the response playbook is predictable. Patch immediately, check for indicators of compromise, reset credentials. The implicit assumption is that these are ordinary software bugs in otherwise sound infrastructure, flaws to fix rather than symptoms of a design problem.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Network security appliances concentrate three properties that attackers value into a single target. They are internet-facing by design. They hold elevated trust positions on the network, terminating VPN sessions, inspecting traffic, and managing access to internal segments. And they run complex proprietary software stacks that resist independent security review.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Most carry no endpoint detection and response agent because the vendors build both the OS and the management plane as a closed system. When a firewall is compromised, the attacker inherits the device's trust position, its visibility into network traffic, and its management access. The compromise is invisible to the security stack because the compromised device is the security stack.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;GTIG noted this detection gap directly, observing that the absence of EDR coverage on routers, firewalls, and VPN appliances creates blind spots that threat actors actively seek. Mandiant's M-Trends 2026 report described edge and core network devices as "frequently uncatalogued and unmonitored" gateways that grant adversaries "invisible, long-term access." Attackers have identified the perimeter security appliance as the point where maximum trust meets minimum visibility, and they are working through the vendor list methodically.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span&gt;&lt;span style="color: #0d7d94;"&gt;What the KEV Catalog Shows&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Cisco leads all security and network infrastructure vendors in KEV entries with 143, a function of both market share and product breadth spanning firewalls, VPN concentrators, switches, routers, and identity services. Ivanti follows at 39, heavily concentrated in Connect Secure and Policy Secure VPN products. Citrix has 31 entries, Fortinet 28, SonicWall 27, Zyxel 16, and Palo Alto Networks 15.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The year-over-year trend is gradual but directional. Security appliance vendors held near 20% of annual KEV additions from 2021 through 2024, then climbed to 21.2% in 2025 and 25.4% in the first half of 2026. That 2026 figure represents the highest annual share since the catalog launched, though the year is incomplete.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/kev_yearly_share.png?width=1481&amp;amp;height=881&amp;amp;name=kev_yearly_share.png" width="1481" height="881" alt="kev_yearly_share" style="height: auto; max-width: 100%; width: 1481px;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Annual KEV additions with security appliance vendor share. 2026 data covers January through July.&amp;nbsp;&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Seventy-five of these entries carry CISA's ransomware flag, marking them as confirmed entry points for ransomware campaigns. Ivanti products lead the ransomware-associated count at 14, followed by SonicWall and Fortinet at 13 each, Cisco and Citrix at 9, and Palo Alto Networks at 6.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The devices that organizations purchase to prevent ransomware intrusions are documented ransomware entry points.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/kev_ransomware_vendors.png?width=1479&amp;amp;height=880&amp;amp;name=kev_ransomware_vendors.png" width="1479" height="880" alt="kev_ransomware_vendors" style="height: auto; max-width: 100%; width: 1479px;"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Security appliance vendor KEV entries flagged as used in known ransomware campaigns.&amp;nbsp;&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Basic Flaws at Root Level&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;The weakness profile explains why exploitation is so productive. Across CRITICAL and HIGH severity CVEs for Ivanti, Fortinet, Palo Alto Networks, SonicWall, Citrix, and Barracuda in NVD, command and code injection accounts for 27% of CWE classifications, making it the largest identified category. OS command injection alone (CWE-78) appears 120 times, and SQL injection (CWE-89) appears 105 times. Path traversal (CWE-22) adds another 80 instances. These are web application security failures that the industry solved decades ago in other contexts. In a network security appliance running at root on the network perimeter, each one hands the attacker the device's full trust position.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Authentication and access-control weaknesses account for 17% of the CWE classifications. Improper authentication (CWE-287, 33 instances), missing authentication for critical functions (CWE-306, 25 instances), and improper access control (CWE-284, 18 instances) appear repeatedly across these vendors. The devices entrusted with enforcing authentication and access control are failing at authentication and access control.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/cwe_categories.png?width=1481&amp;amp;height=880&amp;amp;name=cwe_categories.png" width="1481" height="880" alt="cwe_categories" style="height: auto; max-width: 100%; width: 1481px;"&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;CWE category distribution across CRITICAL and HIGH severity CVEs for six major security appliance vendors.&amp;nbsp;&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;China-aligned threat groups have been the most active exploiters. Trend Micro's analysis attributes at least seven of ten major edge-device exploitation campaigns in 2024-2026 to Chinese espionage operations. Eight distinct clusters targeted Ivanti Connect Secure in early 2024 alone, and sustained campaigns hit Fortinet FortiGate and Citrix NetScaler through 2025 into 2026. The exploitation window has compressed from weeks to days. GreyNoise reported that the gap between patch release and widespread exploitation "has effectively collapsed." Fifty-five security appliance CVEs in the KEV catalog currently carry EPSS scores above 0.9, the highest tier of predicted exploitation probability.&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;span style="color: #0d7d94;"&gt;Treating Appliances as Adversary Targets&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Faster patching is necessary but insufficient. If the architecture concentrates trust in internet-facing devices that attackers can reach before defenders can patch, speed alone is a losing race.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Organizations should treat perimeter security appliances as adversary-accessible endpoints rather than trusted infrastructure. That means deploying network-level detection around the appliances themselves, monitoring for unexpected outbound connections, lateral movement from management interfaces, and configuration changes outside maintenance windows. It means assuming the appliance will be compromised and designing network segmentation so that a compromised firewall or VPN concentrator cannot reach everything behind it. Several vendors now offer integrity monitoring and attestation features for their appliances. If available, enable them.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The longer-term architectural response is distributing security controls away from monolithic perimeter appliances. Zero-trust architectures, identity-aware proxies, and cloud-delivered security reduce the value of compromising any single device by removing the concentration of trust that makes these appliances such productive targets.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Every compromised Ivanti box and exploited FortiGate is a data point in the same argument, that concentrating trust in internet-facing proprietary appliances with no third-party security visibility was always a fragile design. At 21 zero-days per year, vendors cannot patch their way out of the underlying architecture.&lt;/span&gt;&lt;/p&gt; 
&lt;h3&gt;&lt;span style="color: #0d7d94;"&gt;Sources&lt;/span&gt;&lt;/h3&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review)"&gt;Google Threat Intelligence Group, "Look What You Made Us Patch: 2025 Zero-Days in Review," 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"&gt;CISA Known Exploited Vulnerabilities Catalog, retrieved July 24, 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/edge-under-siege-how-state-sponsored-actors-exploit-your-perimeter"&gt;Trend Micro, "Edge Under Siege: How State-Sponsored Actors Exploit Your Perimeter," 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://cloud.google.com/security/resources/m-trends-executive-edition"&gt;Google / Mandiant, M-Trends 2026 Report&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://services.nvd.nist.gov/rest/json/cves/2.0"&gt;NVD API 2.0, CVE data for security appliance vendors, queried July 24, 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://api.first.org/data/v1/epss"&gt;FIRST EPSS API, exploit prediction scores for security appliance CVEs, queried July 24, 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fyour-security-appliances-are-the-attack-surface&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Zero-Day</category>
      <category>Security Appliances</category>
      <category>cisa-kev</category>
      <category>network-security</category>
      <category>perimeter-security</category>
      <category>firewalls</category>
      <category>edge-devices</category>
      <pubDate>Tue, 18 Aug 2026 16:21:41 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/your-security-appliances-are-the-attack-surface</guid>
      <dc:date>2026-08-18T16:21:41Z</dc:date>
      <dc:creator>Jacob Krell</dc:creator>
    </item>
    <item>
      <title>Trump's Hack-Back Memo: Building the Civilian Component</title>
      <link>https://suzulabs.com/suzu-labs-blog/america-just-built-a-public-private-offensive-cyber-program.-the-civilian-component-is-the-part-that-has-to-be-built-right</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/america-just-built-a-public-private-offensive-cyber-program.-the-civilian-component-is-the-part-that-has-to-be-built-right" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/WH%20Blog.png" alt="Trump's Hack-Back Memo: Building the Civilian Component" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="line-height: 1.2; color: #0d0d0d; background-color: #ffffff;"&gt;America Just Built a Public-Private Offensive Cyber Program. The Civilian Component Is the Part That Has to Be Built Right.&lt;/h1&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;The short version&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;On August 12, 2026, President Trump signed a National Security Presidential Memorandum (NSPM), “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” authorizing vetted private U.S. companies to conduct offensive cyber operations, hacking back, against foreign cyber-enabled transnational criminal organizations (CE-TCOs) under federal direction and oversight, run through the National Coordination Center (NCC). I have been publicly arguing for this model for the better part of a year, so I am not going to spend this piece debating whether the concept is sound. I believe it is.&lt;/p&gt;</description>
      <content:encoded>&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;The short version&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;On August 12, 2026, President Trump signed a National Security Presidential Memorandum (NSPM), “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” authorizing vetted private U.S. companies to conduct offensive cyber operations, hacking back, against foreign cyber-enabled transnational criminal organizations (CE-TCOs) under federal direction and oversight, run through the National Coordination Center (NCC). I have been publicly arguing for this model for the better part of a year, so I am not going to spend this piece debating whether the concept is sound. I believe it is.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;What I am going to do instead is the harder thing: lay out how the civilian component of this program should actually be built. The memo gives the two Executive Directors 60 days to write the operating procedures that will govern vetting, targeting, approvals, and the protection of Americans. Those procedures do not exist yet. Every hard question about this program lives in that unwritten document, and the country gets exactly one first draft. Having spent two decades running offensive operations, first in uniform and now leading authorized offensive engagements for enterprise and government clients, I want to put a working blueprint on the table while the drafting window is open.&lt;/p&gt; 
&lt;blockquote style="background-color: #f4f8fd; color: #1a1a1a;"&gt; 
 &lt;p style="color: #1c3e5c; line-height: 1.65;"&gt;The offensive talent already exists in the private sector. What does not exist yet is the civilian machinery to direct it accountably. That machinery is what the next 60 days will decide.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The headline shorthand is already settled meaning that people are viewing these as cyber letters of marque, the digital descendant of the commissions that let privateers hunt enemy shipping under a government’s flag. Critics will reach for the other word — cyber mercenaries. Both labels miss what the document builds. A letter of marque was a standing license which allowed privateers to take the commission, go hunting, keep the prize. This program grants no standing license and pays no prize and every operation requires fresh written approval from two federal executive directors, the target set is restricted to criminal organizations rather than foreign states, and an operation that drifts out of scope must stop and report itself. Congress spent a decade flirting with looser versions of this idea under the banner of active cyber defense, the hack-back bills that never passed, and this memo is tighter than any of them. The privateering analogy is the door people will walk in through. The per-operation control is what should actually be paid attention to.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;This did not appear out of nowhere. It is the end of an eighteen-month chain, and the clock that matters now started with the August 12 signature. One link in that chain has gone almost entirely unremarked in today’s coverage: NSPM-11, the June directive on artificial intelligence in the national security enterprise. I will come back to it, because read next to today’s memo it says something bigger than “companies can hack back”, and the bigger picture is what I think has the most opportunity to turn the tide.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(85).png?width=1464&amp;amp;height=442&amp;amp;name=image%20(85).png" width="1464" height="442" alt="Policy chain leading to the August 2026 hack-back presidential memorandum" style="height: auto; max-width: 100%; width: 1464px;"&gt;&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;What “the civilian component” actually means here&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The program is co-led by the Department of Justice and the Department of Homeland Security, each designating an Executive Director, operating through the NCC. That places this squarely on the civilian side of American cyber power, distinct from what Cyber Command and the intelligence community do under their own authorities. The distinction matters more than most coverage will acknowledge, because the civilian side carries a different set of obligations:&lt;/p&gt; 
&lt;ul style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;li&gt;Protecting U.S. persons and constitutional rights at every step of an operation, not as an afterthought.&lt;/li&gt; 
 &lt;li&gt;Defending critical infrastructure while working with the private sector as a partner rather than treating it as a victim pool or a vendor list.&lt;/li&gt; 
 &lt;li&gt;Keeping every operation below the threshold of armed conflict, deconflicted with the military and intelligence agencies who own the space above it.&lt;/li&gt; 
 &lt;li&gt;Being accountable in ways covert programs are not: contracts, audits, written approvals.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(86).png?width=1452&amp;amp;height=1240&amp;amp;name=image%20(86).png" width="1452" height="1240" alt="Where the civilian component sits within US cyber power, below the armed-conflict threshold" style="height: auto; max-width: 100%; width: 1452px;"&gt;&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Whoever runs the civilian component is not being hired to hack. They are being hired to make sure a powerful new capability operates inside American law and American values while still moving fast enough to hurt the criminal organizations it was built to hurt. That is a different job than offensive operations, and it is a different job than compliance. It requires someone who has lived on both sides.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;Where I stand, and why that history matters&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;In November 2025, talking to TechNewsWorld about China’s espionage machine, I argued the U.S. was fighting the wrong way: adversaries run whole-of-society programs, and the U.S. needed to mirror that by “deepening partnerships between federal agencies and private sector cybersecurity firms that can serve as force multipliers in the cyber fight.” My closing line was that we need to treat companies in strategic sectors as partners, not just victims to be protected. Days later, commenting on Operation Endgame 3.0, I made the operational version of the same point: sustained disruption of the cybercrime ecosystem only works through a public-private collaboration model, because impact is measured in disruption cost and defender advantage, not permanence. And in December 2025, when the National Cyber Strategy first signaled a private-sector turn on offense, my stated concern was execution speed, whether the government could engage private talent fast enough to matter.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;This memo is that argument written into national policy. I am glad it exists. But advocating for a capability obligates you to hold it to the standard you set when you asked for it. The rest of this piece is me doing that work: not a critique from the sidelines, but the operating model I would build if I were holding the pen.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;How the hack-back program’s operating procedures should be written&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Section 3 of the memo lists fourteen things the procedures must accomplish. Here is how I would build the load-bearing pieces. None of this is theoretical for me; it is the discipline any serious offensive firm already runs on every authorized engagement, scaled up to a national program.&lt;/p&gt; 
&lt;h3 style="color: #1a1a1a; background-color: #ffffff;"&gt;Vetting: qualify operators, not just companies&lt;/h3&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The memo’s minimum standards (Sec. 3(a)(i)) name technical proficiency, proven performance, facility security, personnel vetting, and reliability. The mistake to avoid is vetting at the corporate logo level. Offensive capability lives in specific people and specific methodology, and a company’s marketing deck tells you nothing about either. The vetting rubric should require a demonstrated-operations portfolio reviewed by cleared assessors, named and cleared operators on every package rather than interchangeable staff, and an examination of the firm’s internal authorization discipline: how it scopes, how it documents, how it stops when something drifts. A firm that cannot show you its own rules of engagement in writing should not be trusted with the government’s.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The small-firm provision (Sec. 3(a)(ii)) is the sleeper clause of the whole memo, and it needs to be real rather than decorative. The last decade of offensive talent leaving government did not flow to three primes; it dispersed into small specialist shops. If the on-ramp requires prime-scale infrastructure just to apply, the program will have locked out the exact operators it was created to reach. Build a tiered entry: full participants for firms that clear every bar, and a sponsored track where a specialist operates on discrete tasks under the facility and contract umbrella of a full participant or the government itself, with the same per-operation approval discipline. Capability should gate participation. Overhead should not. The same tiering logic should govern the memo’s financial gate, a bond or escrow of at least $1 million, forfeited if a company violates its contract (Sec. 3(a)(iv)). Skin in the game is the right instinct, but let a sponsored specialist’s bond sit at the umbrella level so the gate screens for seriousness rather than balance-sheet size.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(87).png?width=1442&amp;amp;height=830&amp;amp;name=image%20(87).png" width="1442" height="830" alt="Tiered on-ramp keeping the memo's small-firm provision real: capability gates entry, overhead does not" style="height: auto; max-width: 100%; width: 1442px;"&gt;&lt;/p&gt; 
&lt;h3 style="color: #1a1a1a; background-color: #ffffff;"&gt;Per-operation approval: make the package do the work&lt;/h3&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The memo’s best feature is that both Executive Directors must give written approval before every single operation (Sec. 3(a)(xiv)). No standing licenses. To make that real at operational tempo, the standardized package (Sec. 3(a)(vii)) has to carry the entire decision: attribution evidence graded against a published confidence standard, blast-radius analysis covering every system the operation could plausibly touch in transit, a U.S.-person exposure assessment reviewed by DOJ before the directors ever see it, defined abort criteria, and the specific effect requested — nothing broader. If the package is rigorous, approval can be fast. If approval is slow, firms will quietly push for broader authorizations to compensate, and broad authorizations are precisely how a disciplined program becomes an undisciplined one. Speed and safety are not in tension here; they are both products of the same paperwork discipline.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image-png-2.png?width=1448&amp;amp;height=1532&amp;amp;name=image-png-2.png" width="1448" height="1532"&gt;&lt;/p&gt; 
&lt;h3 style="color: #1a1a1a; background-color: #ffffff;"&gt;Deconfliction: an intake, not a meeting&lt;/h3&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The classified annex on deconfliction (Sec. 3(a)(v)) has to function as standing infrastructure: a real-time intake where every proposed target is checked against DOJ, DHS, State, Treasury, War Department, and intelligence community equities before a package advances, with a hard hold anytime an equity flags. The oldest and most legitimate objection to private-sector operations is a company blundering into a live government operation. A quarterly coordination meeting does not answer that objection. A queryable, always-on process does.&lt;/p&gt; 
&lt;h3 style="color: #1a1a1a; background-color: #ffffff;"&gt;Protecting Americans: minimization as muscle memory&lt;/h3&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The stop-and-report rule (Sec. 3(a)(x)) — halt, minimize, and notify the moment an operation touches a U.S. person or drifts out of scope — is the single provision that will make or break public trust in this program. The procedures should require every participating firm to demonstrate its minimization workflow live, during vetting, before its first operation is ever approved. Not a policy PDF. A demonstration: here is the trigger, here is who calls it, here is what gets preserved for the record, here is the notification hitting the NCC. In the military we never treated rules of engagement as a document; they were drilled until they were reflex. Civilian offensive operations deserve the same standard, because the first firm that hides an overreach instead of reporting it will hand opponents of this program everything they need to kill it.&lt;/p&gt; 
&lt;h3 style="color: #1a1a1a; background-color: #ffffff;"&gt;The annual re-evaluation: keep the bar honest&lt;/h3&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Continued participation is reviewed at least yearly (Sec. 3(a)(xiii)). Use it. Firms that cut corners, pad attribution confidence, or treat disclosure obligations casually should exit the program before they generate the incident that discredits it. A program that never removes anyone has no bar. Treat it as continuous validation at the end of every engagement. Annual checks on the over compliance of each engagement.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;AI in offensive cyber operations: kept on a human leash&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;There is a capability running through all of this that the memo mentions only in passing and the procedures cannot afford to treat as an afterthought — artificial intelligence. AI has already changed what a small team can do offensively. It enumerates infrastructure, correlates scattered intelligence into a coherent target picture, drafts and adapts tooling, and works through a target’s environment at a tempo a human crew cannot sustain. Any honest design of this program has to account for that, because the criminal organizations on the other end already do. Leaving AI out of the equation is not caution. It is preparing for the last war.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Here is where I expect Washington to take the wrong turn. The reflex will be to treat AI as something to procure from the foundational model providers — hand the hard problems to the big labs and let them bolt an offensive capability onto a general-purpose model. That is a mistake, and the evidence is sitting in public. Those same providers cannot reliably keep their own models inside the guardrails they built for a chat window. We watch the models get jailbroken, prompt-injected, and talked into behavior their makers swore was contained; we watch agentic versions take actions no one authorized. When OpenAI’s models hacked HuggingFace it was a clear sign that the correct precautions where not taken. A company that cannot keep its model in its lane inside a customer-support widget is not the company to trust with autonomous operations against a foreign target under color of federal authority.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The answer is not to keep AI out. It is to keep AI controlled. The right model is an agentic harness with a skilled operator in the loop on every consequential decision, the doctrine my firm has built our AI Offensive Security practice around, and what the trademark we hold, Hacker in the Loop, means in actual operation. The machine does the heavy, fast, tireless work: enumerate, correlate, propose, draft. A cleared human decides. The AI never earns the authority to cross a boundary on its own, not to escalate from surveillance to effect, not to reach into a system that was not in the approved package, not to act inside the United States. The memo already encodes this principle in Section 3(a)(xiv): a human authorizes every operation, in writing, before anyone acts. An autonomous agent proposing and executing its own operations is fundamentally incompatible with that rule. AI belongs inside the harness accelerating the operator. It does not belong holding the trigger. The human (read hacker) in the loop holds the responsibility at the end of the day.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;And here is the part of today’s coverage that is missing entirely: the government has already committed itself to this model, in writing, twice.&lt;span&gt; &lt;/span&gt;&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/"&gt;NSPM-11&lt;/a&gt;, signed June 5, requires that every AI system adopted across the national security enterprise be “reliable, robust, steerable, and controllable,” and its Accountability pillar keeps commanders, directors, and agency heads personally responsible for what AI does at every level of command. It even bars any commercial entity from retaining the power to disable, degrade, or materially modify a mission system without the government’s knowledge and approval. Nine weeks later, today’s memo requires written human approval before every operation — while its own Section 3(b) directs the NCC to “utilize automation to streamline Program elements wherever appropriate.” Put the two directives side by side: a controllable machine, an accountable human, authorization in writing before anything consequential happens. That is one doctrine, stated in two documents five months apart, and it is the same architecture I just described. The June memorandum puts the machine on a leash. The August memo hands the leash to a person. The drafters of the operating procedures should keep both documents on the table, because the government has now told us twice what it expects the relationship between the AI and the human to be.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image-png-3.png?width=1448&amp;amp;height=642&amp;amp;name=image-png-3.png" width="1448" height="642"&gt;&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;That points straight at who should be building this. Not the model labs, who understand training runs but not rules of engagement, not deconfliction, and not what it means to be wrong about a target in a foreign country. The people who can build a controlled offensive AI harness and sit across the table from the intelligence community to make targeting and authorization calls are a narrow group: operators fluent in both the AI and the tradecraft, cleared to be in the room where those decisions happen, and disciplined enough to keep the machine on the leash. That is exactly the specialized depth the small-firm provision was written to reach, and exactly where the government has the thinnest bench of its own.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;The hard problems, and what the civilian program office does about each&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;My analytical read of this memo flagged real risks. A leader’s obligation is to pair every risk with the control that manages it, so here is that pairing, summarized first and argued below.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image-png-4.png?width=1454&amp;amp;height=804&amp;amp;name=image-png-4.png" width="1454" height="804"&gt;&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;strong&gt;The legal foundation is a theory.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The program rides on the Computer Fraud and Abuse Act (CFAA) carve-out for “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency” stretching to cover supervised private companies. That is untested, and an executive memo cannot override a statute. The civilian program office should do two things from day one: build a documented authorization chain of custody for every operation, written direction, named supervising officials, and contemporaneous records. If the theory is ever tested in court, the government’s supervision is a provable fact rather than a characterization; and push openly for Congress to codify the authority and liability protection. A program built on durable statute survives administrations. A program built on a memo is one signature from erasure, and every participating firm knows it. No one wants to be burned.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;strong&gt;The state-actor presumption invites escalation.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The memo assumes a criminal group is not state-operated “unless clear intelligence exists establishing such connection.” In the real world that line is deliberately blurry, and plenty of the worst crews operate with their government looking the other way or taking a cut. The targeting adjudication framework (Sec. 3(a)(vi)) is where this gets managed: require an affirmative state-nexus assessment on every package, not just a check for disqualifying intelligence, and route anything with an ambiguous nexus to the interagency rather than letting the presumption default it into the approval queue. The presumption as written leans toward action. Adjudication discipline is what leans it back.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;strong&gt;Surveillance and effects blur in live operations.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The memo’s surveillance definition includes breaking in and limited manipulation to stay hidden, which means “surveillance” here is a real intrusion, and the line between watching and acting is one of intent and degree. The procedures should treat any manipulation beyond the approved surveillance scope as a new operation requiring new written approval, full stop. Ambiguity in that seam is where operators freelance, and freelancing is what this entire architecture exists to prevent.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;strong&gt;The intelligence funnel is wide.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;Participating companies can ingest threat data that other firms collected in their normal course of business. That is a powerful engine for proposing well-scoped operations, and it is also how a security vendor’s customer telemetry quietly becomes targeting input. The disclosure requirement (Sec. 3(a)(iii)) should be enforced with teeth, and the program should publish guidance on what participating firms owe the upstream customers whose data feeds the pipeline. Trust in the funnel is trust in the program.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image-png-Aug-13-2026-04-16-17-1534-PM.png?width=1442&amp;amp;height=746&amp;amp;name=image-png-Aug-13-2026-04-16-17-1534-PM.png" width="1442" height="746"&gt;&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;&lt;strong&gt;Offense cannot outrun defense.&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;My CTO, Denis Calderone, made this point in March 2026 and it still stands: if we lean into offensive cyber, defensive investment has to keep pace, and standing up this program in the same year the administration proposed cutting CISA’s budget by more than $700 million sends a mixed signal. The civilian component sits inside the Homeland Security apparatus. Its leadership should be a voice for resourcing the whole fight, not just the exciting half.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;What leading the civilian component actually requires&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;By roughly October 11, 2026, the procedures will exist, and shortly after that, so will the first cohort of participating companies. Then the question becomes who runs this day to day — who the directors, the firms, and eventually Congress trust to hold the line. Based on everything above, the profile is fairly clear.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Start with someone who has actually conducted offensive operations under rules of engagement and a chain of command, because you cannot supervise work you have never done, and operators can tell within minutes whether the person across the table has been on the keyboard. They need to have run the accountability side too which means scoping, written authorization, documentation, and the discipline of stopping at the right time. The civilian component’s product is not access, it is trust. They have to understand how to put AI to work on offense and, more importantly, how to keep it on a human leash, because that capability is arriving whether the program plans for it or not. A clearance is non-negotiable; the deconfliction and targeting frameworks live in classified annexes, and the person running this has to live there with them. The private sector should regard them as one of its own rather than a regulator, because this program only works if the best firms want in. And they need a public record of straight talk about the program’s weaknesses as well as its promise, because the first time something goes wrong (and in operations, something always goes wrong) the person explaining it to the public needs credibility they banked before the incident, not after.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;People matching that profile exist. There are not many of them, and most of the ones I know left government service in the past decade and are running the private-sector teams this memo was written to reach. That is not a problem for the program. It is the point of the program.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;What the memo gets right&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Credit where due, because the document is more carefully built than the failed hack-back bills that preceded it. Per-operation written approval with two independent sign-offs. A hard ceiling excluding anything lethal or war-triggering. Interagency deconfliction as a requirement rather than a courtesy. A mandatory stop-and-report obligation when operations drift. A target set restricted to criminal organizations precisely so the program stays below the threshold of armed conflict. And explicit room for smaller specialist firms, the provision I pushed for specifically, because the offensive talent that left government over the last decade is a national asset sitting in exactly those shops.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Whoever drafted this studied why every previous attempt died and answered the objections one by one. The design intent is genuinely good. The execution is a 60-day promissory note, which is why the drafting window matters more than the signing ceremony.&lt;/p&gt; 
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;Bottom line&lt;/h2&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;The United States just formally declared the private sector an offensive instrument of national power against cyber-enabled crime. I asked for that, publicly and repeatedly, and I stand by it. But the version I argued for treats private firms as cleared, disciplined, accountable partners operating inside real machinery and vetted operator by operator, approved operation by operation, deconflicted in real time, and drilled to stop and report the moment something drifts. That machinery is the civilian component, and it gets built in the next 60 days or it gets improvised afterward at much higher cost.&lt;/p&gt; 
&lt;p style="color: #1a1a1a; background-color: #ffffff;"&gt;Building it well takes people who understand the whole problem covering the offensive craft, because the criminal organizations on the other end are genuinely good at this; AI as a force multiplier that has to stay under human command, because it is already on the field; and the civilian guardrails, because the program answers to American law and American citizens. I have spent almost twenty years working that exact seam, in uniform and out, and my firm and I intend to be useful to the people writing these procedures in whatever way serves the mission. The country finally built the on-ramp. Now it has to be worth driving onto.&lt;/p&gt;  
&lt;h2 style="color: #0d0d0d; background-color: #ffffff;"&gt;Frequently asked questions&lt;/h2&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;em&gt;&lt;strong&gt;Is hacking back legal now in the U.S.?&lt;/strong&gt;&lt;/em&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;Only inside this program. For everyone else, reaching into someone else’s systems remains a federal crime under the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. 1030). The memo’s legal theory is that vetted companies operating “on behalf of and under the supervision of” DOJ or DHS fit the CFAA’s carve-out for lawfully authorized law-enforcement activity. That theory is untested in court, and state and foreign computer-crime laws still apply.&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;em&gt;&lt;strong&gt;What is the National Coordination Center (NCC)?&lt;/strong&gt;&lt;/em&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;The NCC is the body created inside the Department of Homeland Security apparatus by Executive Order 14159 in January 2025. Under the August 12, 2026 memo, it runs the private-sector offensive cyber program, overseen by two Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, who must jointly approve every operation in writing.&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;em&gt;&lt;strong&gt;Can private companies conduct cyber attacks for the U.S. government?&lt;/strong&gt;&lt;/em&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;As of August 12, 2026, yes, within strict limits. Vetted Participating Companies under contract with DOJ or DHS can conduct cyber surveillance and cyber effects operations against foreign criminal organizations, but only with per-operation written approval from both Executive Directors, and never anything likely to cause loss of life or rise to a use of force under international law. DO NOT JUST START HACKING BACK!&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;em&gt;&lt;strong&gt;What is a CE-TCO?&lt;/strong&gt;&lt;/em&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;A Cyber-Enabled Transnational Criminal Organization: a foreign criminal group that commits cyber-enabled crimes against the United States and is not an institutional part of a foreign government or wholly operated under a government’s direction. The memo presumes a group is not state-operated unless clear intelligence establishes the connection — a presumption that, as I argue above, needs an affirmative state-nexus check in practice.&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;em&gt;&lt;strong&gt;What is the $1 million bond requirement for participating companies?&lt;/strong&gt;&lt;/em&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;Section 3(a)(iv) of the memo lets DOJ and DHS require participating companies to post a bond or escrow of at least $1,000,000, forfeited if the company violates its contract. It is the program’s financial stake and unless the operating procedures tier it, a hard floor on which firms can afford to participate.&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;strong&gt;&lt;em&gt;Are these cyber letters of marque?&lt;/em&gt;&lt;/strong&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;It is the closest historical analogy, but the program is more controlled than privateering ever was. A letter of marque was a standing license with a prize at the end. This program grants no standing licenses and pays no prizes: every operation requires fresh written approval from two federal directors, targets are restricted to criminal organizations, and an operation that drifts out of scope must stop and report itself.&lt;/p&gt; 
&lt;/div&gt; 
&lt;div style="color: #1a1a1a; background-color: #ffffff;"&gt; 
 &lt;div style="color: #0d0d0d;"&gt;
  &lt;strong&gt;&lt;em&gt;How does NSPM-11 relate to the hack-back memo?&lt;/em&gt;&lt;/strong&gt;
 &lt;/div&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;NSPM-11 (June 5, 2026) governs artificial intelligence across the national security enterprise. It requires AI systems to be reliable, robust, steerable, and controllable, and it holds commanders, directors, and agency heads accountable for AI’s conduct through the chain of command. The August 12 memo requires written human approval before every private-sector cyber operation. Read together, the two directives describe one operating doctrine: machines provide speed and scale, and a named, accountable human authorizes every consequential action.&lt;/p&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;&lt;strong&gt;&lt;strong style="color: #555555; background-color: #ffffff;"&gt;Primary source:&lt;/strong&gt;&lt;/strong&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; &lt;/span&gt;&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" style="background-color: #ffffff;"&gt;Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” (Aug 12, 2026)&lt;/a&gt;&lt;br style="color: #555555; background-color: #ffffff;"&gt;&lt;strong&gt;&lt;strong style="color: #555555; background-color: #ffffff;"&gt;Companion:&lt;/strong&gt;&lt;/strong&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; &lt;/span&gt;&lt;a href="https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-expands-capabilities-to-combat-transnational-cyber-enabled-crime/" style="background-color: #ffffff;"&gt;White House Fact Sheet&lt;/a&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; · &lt;/span&gt;&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/" style="background-color: #ffffff;"&gt;EO 14390 (Mar 6, 2026)&lt;/a&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; · &lt;/span&gt;&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/" style="background-color: #ffffff;"&gt;NSPM-11, “Artificial Intelligence in the National Security Enterprise” (Jun 5, 2026)&lt;/a&gt;&lt;br style="color: #555555; background-color: #ffffff;"&gt;&lt;strong&gt;&lt;strong style="color: #555555; background-color: #ffffff;"&gt;Prior coverage:&lt;/strong&gt;&lt;/strong&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; &lt;/span&gt;&lt;a href="https://www.technewsworld.com/story/us-think-tank-waves-red-flag-over-chinese-economic-espionage-180009.html" style="background-color: #ffffff;"&gt;TechNewsWorld, Nov 2025&lt;/a&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; · &lt;/span&gt;&lt;a href="https://itnerd.blog/2025/11/13/three-destructive-malware-networks-taken-down-in-operation-endgame-3-0/" style="background-color: #ffffff;"&gt;Operation Endgame 3.0, Nov 2025&lt;/a&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; · &lt;/span&gt;&lt;a href="https://www.scworld.com/news/trump-cyber-policy-focuses-on-offensive-operations-harnessing-ai" style="background-color: #ffffff;"&gt;SC Media, Mar 2026&lt;/a&gt;&lt;span style="color: #555555; background-color: #ffffff;"&gt; · &lt;/span&gt;&lt;a href="https://nationalinterest.org/blog/buzz/us-cant-always-arrest-cyber-scammers-but-doesnt-have-to-let-them-in-ps-072926" style="background-color: #ffffff;"&gt;The National Interest, Jul 2026&lt;/a&gt;&lt;/p&gt; 
 &lt;p style="color: #333333; line-height: 1.7;"&gt;&amp;nbsp;&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Famerica-just-built-a-public-private-offensive-cyber-program.-the-civilian-component-is-the-part-that-has-to-be-built-right&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI Security</category>
      <category>National Security</category>
      <category>Cyber Policy</category>
      <category>Cybercrime</category>
      <category>Thought Leadership</category>
      <category>Hack Back</category>
      <category>Public-Private Partnership</category>
      <category>Offensive Cyber</category>
      <category>National Coordination Center</category>
      <pubDate>Thu, 13 Aug 2026 18:04:03 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/america-just-built-a-public-private-offensive-cyber-program.-the-civilian-component-is-the-part-that-has-to-be-built-right</guid>
      <dc:date>2026-08-13T18:04:03Z</dc:date>
      <dc:creator>Mike Bell</dc:creator>
    </item>
    <item>
      <title>The Agent Identity Problem: Non-Human Identities Outnumber Humans 45 to 1 and AI Agents Are Making It Worse</title>
      <link>https://suzulabs.com/suzu-labs-blog/the-agent-identity-problem-non-human-identities-outnumber-humans-45-to-1-and-ai-agents-are-making-it-worse</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/the-agent-identity-problem-non-human-identities-outnumber-humans-45-to-1-and-ai-agents-are-making-it-worse" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/image%20(74).png" alt="The Agent Identity Problem: Non-Human Identities Outnumber Humans 45 to 1 and AI Agents Are Making It Worse" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;The Agent Identity Problem: Non-Human Identities Outnumber Humans 45 to 1 and AI Agents Are Making It Worse&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;span&gt;The Agent Identity Problem: Non-Human Identities Outnumber Humans 45 to 1 and AI Agents Are Making It Worse&lt;/span&gt;&lt;/p&gt;  
&lt;h3 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/h3&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Non-human identities already outnumber humans 45 to 1 in the average enterprise, and agentic AI is compounding that ratio faster than IAM teams can govern it.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;/span&gt;Agent framework downloads outpace security tooling 83 to 1 on PyPI, a gap that widened 41% between January and May 2026.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Ninety-two percent of organizations say their current IAM tools cannot manage AI agent identities.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;One in three agent framework CVEs involves identity, credential, or access control flaws, based on 77 CVEs analyzed from NVD.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Attackers exploit exposed AWS credentials within an average of 17 minutes, while nearly a quarter of organizations take over 24 hours to rotate them.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Sixty-four percent of secrets confirmed as exposed in 2022 remained valid four years later.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Forty percent of live Model Context Protocol (MCP) servers in a study of nearly 8,000 had zero authentication, and every OAuth-enabled server tested carried at least one flaw.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt; Why Agents Break the Identity Model&lt;/span&gt;&lt;span style="white-space-collapse: preserve;"&gt;&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;A service account sits in one system, holds one credential, does one job. An AI agent acquires permissions dynamically at runtime, spawns sub-agents, invokes external APIs, writes and executes code, and chains actions across dozens of systems in a single task. The blast radius of a compromised agent credential dwarfs what a static service account could produce, yet only 22% of security teams treat agents as independent identities.&lt;/span&gt;&lt;span style="white-space-collapse: preserve;"&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;A 2026 survey from the Cloud Security Alliance (CSA) quantified the gap with numbers that should alarm any Identity and Access Management (IAM) team. Ninety-two percent of respondents said their legacy IAM tools cannot manage AI and NHI risks, and half reported no clear ownership or accountability for agent identities. A separate CSA survey found that only 28% of organizations can trace an agent's actions back to a human sponsor across all environments.&lt;/span&gt;&lt;span style="white-space-collapse: preserve;"&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;These gaps are already being exploited. Nearly half of organizations have reported breaches involving non-human identities, and two-thirds have suffered successful cyberattacks from compromised NHIs. The Salesloft-Drift breach in August 2025 illustrated what this looks like in practice when the threat actor UNC6395 stole OAuth tokens from a single Drift integration and targeted Salesforce instances across over 700 potentially impacted organizations. No malware required, just token abuse at integration speed. Vercel's April 2026 breach ran the same play, with a compromised third-party OAuth integration exposing database secrets, signing keys, and customer credentials.&lt;/span&gt;&lt;span style="white-space-collapse: preserve;"&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Over-permissioning is the accelerant. A 2025 report from the Non-Human Identity Management Group (NHIMG) found that 73% of secrets held by NHIs carry excessive permissions, and over 5.5% of AWS machine identities have full administrative privileges. When an AI agent inherits or acquires a credential at that privilege level, the distance between "authorized to do its job" and "authorized to do anything" collapses to zero. OWASP's Agentic Security Initiative classifies this pattern under ASI03 (Identity and Privilege Abuse).&lt;/span&gt;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="white-space-collapse: preserve;"&gt; &lt;/span&gt;&lt;span style="color: #0d7d94;"&gt;The Adoption-Governance Gap, Measured&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;We quantified the adoption-governance gap directly using PyPI download data. Agent framework packages, including LangChain, LangGraph, CrewAI, OpenAI Agents SDK, LlamaIndex, and PydanticAI among others, pulled 483 million downloads in May 2026. Agent security and guardrails packages pulled 5.8 million in the same month, an 83-to-1 ratio that reveals just how far deployment is outrunning governance.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;That ratio is widening. In January 2026 it was 59 to 1. By May, 83 to 1, a 41% increase in five months. Agent capability adoption is leaving security tooling further behind each month.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/adoption_governance_gap.png?width=1486&amp;amp;height=733&amp;amp;name=adoption_governance_gap.png" width="1486" height="733" alt="adoption_governance_gap" style="height: auto; max-width: 100%; width: 1486px;"&gt;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;The Credential Lifecycle Gap&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;GitGuardian's 2026 State of Secrets Sprawl report measured 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34% year-over-year increase. AI-assisted development is driving much of that growth. AI-service secrets surged 81% to 1.275 million exposed credentials, and Claude Code co-authored commits leaked secrets at roughly twice the baseline rate.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;MCP introduced a new exposure vector entirely. In the protocol's first year of adoption, 24,008 unique secrets appeared in MCP configuration files on public GitHub, partly because quickstart guides normalized hardcoding API keys directly into configuration files.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The remediation side is where the gap becomes structural. GitGuardian retested secrets confirmed as valid in 2022 and found that 64% were still not revoked by January 2026, representing four years of exposure for credentials that should have been rotated within hours. The attacker-defender timing asymmetry makes this negligence lethal. When AWS credentials appear publicly, attackers attempt access within an average of 17 minutes, while nearly a quarter of organizations take more than 24 hours to rotate exposed credentials. That is an 85x speed gap working in the attacker's favor.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Every AI agent deployed with a long-lived credential inherits that asymmetry.&lt;/span&gt;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;The Agent Identity Blast Radius Model&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Cross-referencing CSA, NHIMG, and ManageEngine data, we modeled what agent identity sprawl looks like for a 1,000-employee organization. The numbers compound fast. Only 12% of organizations have automated lifecycle management. The other 88% run on spreadsheets and hope.&lt;/span&gt;&lt;/p&gt; 
&lt;div style="overflow-x: auto; max-width: 100%; width: 100%; margin-left: auto; margin-right: auto;"&gt; 
 &lt;table style="width: 100%; border-collapse: collapse; table-layout: fixed; border: 1px solid #99acc2;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Step&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Calculation&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;Result&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Total Employees&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Baseline&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;1,000&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;NHI's at 45:1 ratio (CSA)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;1,000 X 45&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;45,000&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;NHI's with over-priveleged secrets (73%, NHIMG)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;45,000 X 0.73&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;~32,850&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Full admin access (5.5%,NHMIG)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;45,000 X 0.055&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;~2,475&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;NHI's after 2 years at 44% YoY (Entro)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;&lt;span&gt;45,000 x 1.44²&lt;/span&gt;&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;~93,312&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Governed by automation (12%)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;93,312 X 0.12&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;~11,197&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;Manually managed (88%)&lt;/td&gt; 
    &lt;td style="width: 33.2833%; padding: 4px;"&gt;93,312 X 0.88&lt;/td&gt; 
    &lt;td style="width: 33.2845%; padding: 4px;"&gt;~82,115&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
&lt;/div&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;AI agents compound the sprawl because each agent deployed with enterprise credentials creates new OAuth grants, API tokens, and service accounts. Spawned sub-agents inherit or escalate those credentials, and every MCP server connection introduces an authentication surface that most organizations have not evaluated.&lt;br&gt;&lt;br&gt;A measurement study of 7,973 live remote MCP servers found that 40% had no authentication at all. The servers that did implement OAuth fared little better, with every single one of the 119 OAuth-enabled servers tested carrying at least one authentication flaw. Dynamic client registration vulnerabilities affected 96.6%, and the researchers obtained 9 CVEs from the study.&lt;br&gt;&lt;br&gt;Agent frameworks themselves carry identity vulnerabilities baked into the code that organizations are deploying at scale. Analysis of 77 CVEs across LangChain, CrewAI, AutoGen, and LlamaIndex shows that 32% involve identity, credential, or access control flaws, and 73% of all agent framework CVEs are rated CRITICAL or HIGH. Q1 2026 set a record with 14 agent framework CVEs in a single quarter.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/cve_category_breakdown.png?width=1334&amp;amp;height=654&amp;amp;name=cve_category_breakdown.png" width="1334" height="654" alt="cve_category_breakdown" style="height: auto; max-width: 100%; width: 1334px;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;A single MCP server connecting an AI agent to a production database with hardcoded credentials, no authentication, and no scoping is the default configuration.&lt;/span&gt;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;The Regulatory Response vs. Reality&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;NIST's National Cybersecurity Center of Excellence and the Coalition for Secure AI both published agent identity guidance in early 2026, and the direction is consistent. Agents need first-class identities with zero-standing privilege, short-lived credentials, and code-bound attestation. Ninety-two percent of organizations told the CSA their IAM tools cannot deliver it. Agent deployment is not waiting for IAM teams to catch up.&lt;/p&gt; 
&lt;h3 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;What Organizations Should Do Now&lt;/span&gt;&lt;/h3&gt; 
&lt;p&gt;Kill long-lived agent credentials. Every AI agent should receive short-lived, task-scoped tokens through a credential broker or gateway. The credential expires when the task completes. Sub-agent credentials should be scoped more narrowly than the parent's, never equal.&lt;br&gt;&lt;br&gt;Treat MCP servers as a first-class attack surface. Forty percent have no authentication. OAuth 2.1 is the minimum, with per-tool authorization and human-in-the-loop approval for destructive actions.&lt;br&gt;&lt;br&gt;Measure credential lifecycle speed. If revoking a compromised agent credential takes days, the organization operates 85x slower than the attacker who exploited it within minutes. Automated revocation triggered by exposure detection is the target state.&lt;br&gt;&lt;br&gt;Identity governance spent decades solving for humans. Humans are now the minority of the identity population. AI agents will push the ratio from 45 to 1 to numbers the current IAM architecture was never designed to hold. Organizations that extend governance to agents will contain the blast radius. Those still running on legacy IAM will find out what an unmanaged agent credential can do at machine speed.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;h2 style="font-weight: bold;"&gt;&lt;span style="color: #0d7d94;"&gt;Sources&lt;/span&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://cloudsecurityalliance.org/artifacts/state-of-nhi-and-ai-security-survey-report"&gt;Cloud Security Alliance, "State of Non-Human Identity and AI Security Survey Report," 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/"&gt;Cloud Security Alliance, "The Non-Human Identity Governance Vacuum," CSA Labs whitepaper, May 2026&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://labs.cloudsecurityalliance.org/agentic/agentic-identity-governance-framework-v1/"&gt;&lt;span&gt;Cloud Security Alliance, "Agent Identity Governance Framework," CSA Labs, 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents"&gt;&lt;span&gt;Cloud Security Alliance / Strata Identity, "Securing Autonomous AI Agents," survey report, February 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.oasis.security/resources/reports/2024-esg-report-managing-non-human-identities"&gt;&lt;span&gt;ESG / Oasis Security, "2024 ESG Report: Managing Non-Human Identities"&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://nhimg.org/2025-state-of-non-human-identities-and-secrets-in-cybersecurity"&gt;&lt;span&gt;NHIMG / Entro Security, "2025 State of Non-Human Identities and Secrets"&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://nhimg.org/the-nhi-secrets-risk-report)"&gt;&lt;span&gt;NHIMG / Entro Security, "NHI &amp;amp; Secrets Risk Report, H1 2025"&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.manageengine.com/news/manageengine-enterprise-identity-security-2026-study.html"&gt;&lt;span&gt;ManageEngine, "Identity Security Outlook 2026," January 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.gitguardian.com/state-of-secrets-sprawl-report-2026"&gt;&lt;span&gt;GitGuardian, "State of Secrets Sprawl 2026," March 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd"&gt;&lt;span&gt;NIST NCCoE, "Accelerating the Adoption of Software and AI Agent Identity and Authorization," concept paper, February 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.coalitionforsecureai.org/whos-minding-the-agent-a-new-framework-for-ai-identity-and-access-control/"&gt;&lt;span&gt;Coalition for Secure AI (CoSAI), "Agentic Identity and Access Management," March 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.token.security/blog/the-2026-data-breach-investigations-report-confirms-it-identity-is-the-control-plane-for-agentic-ai"&gt;&lt;span&gt;Token Security, "The 2026 DBIR Confirms It: Identity Is the Control Plane for Agentic AI," 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"&gt;&lt;span&gt;OWASP Top 10 for Agentic Applications, ASI03 (Identity and Privilege Abuse), 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift"&gt;&lt;span&gt;Google Threat Intelligence Group (GTIG), "Widespread Data Theft Targets Salesforce Instances via Salesloft Drift," August 2025&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://arxiv.org/abs/2605.22333"&gt;&lt;span&gt;Zhou et al., "A First Measurement Study on Authentication Security in Real-World Remote MCP Servers," arXiv:2605.22333, 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://pypistats.org/"&gt;&lt;span&gt;PyPI Stats API, package download data queried June 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://services.nvd.nist.gov/rest/json/cves/2.0"&gt;&lt;span&gt;NVD API, CVE data for agent frameworks queried June 2026&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fthe-agent-identity-problem-non-human-identities-outnumber-humans-45-to-1-and-ai-agents-are-making-it-worse&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>MCP Security</category>
      <category>Credential Management</category>
      <category>AI Agents</category>
      <category>Non-Human-Identity</category>
      <category>Machine Identity</category>
      <pubDate>Fri, 24 Jul 2026 18:14:51 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/the-agent-identity-problem-non-human-identities-outnumber-humans-45-to-1-and-ai-agents-are-making-it-worse</guid>
      <dc:date>2026-07-24T18:14:51Z</dc:date>
      <dc:creator>Jacob Krell</dc:creator>
    </item>
    <item>
      <title>CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't</title>
      <link>https://suzulabs.com/suzu-labs-blog/cmmcs-third-party-assessments-are-paused.-the-standard-of-care-isnt</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/cmmcs-third-party-assessments-are-paused.-the-standard-of-care-isnt" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/ChatGPT%20Image%20Jul%2020%2c%202026%2c%2001_55_53%20PM.png" alt="CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;On July 13 the Department of War suspended Phase 2 of CMMC, the third party certification requirement that was set to start this November. Half the defense industrial base exhaled. The other half is furious.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;On July 13 the Department of War suspended Phase 2 of CMMC, the third party certification requirement that was set to start this November. Half the defense industrial base exhaled. The other half is furious.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Let me put my bias on the table before I say anything else. I do not run a C3PAO and I do not sell certifications. My work is readiness and cyber security advisory and consulting, so I have no certificate revenue to protect and no reason to tell you the sky is falling. That said, I have spent years helping companies build toward CMMC, so I know exactly what this pause feels like for the people who were mid-journey.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Here is what moved and what did not.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The suspension killed the third party assessment requirement, along with the later phases that would have followed. Phase 1 is still here. You still self assess against NIST 800-171. You still post your score in SPRS and sign the annual affirmation. DFARS 252.204-7012 has required contractors to protect covered defense information since 2017, and it is fully intact. All 110 controls are still the standard. Nothing about the level of security expected of you got easier. The only piece that went away is the outside party who was going to check your work.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(70).png?width=726&amp;amp;height=608&amp;amp;name=image%20(70).png" width="726" height="608" alt="image (70)" style="height: auto; max-width: 100%; width: 726px;"&gt;&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;This pause was coming, and the government knew it&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;You will see a lot of relief being expressed online this week from those excited that their mad dash to tighten up their program and get the C3PAO in place, along with the spend that goes with it, was just put on hold. Be careful with that. The relief is well earned, but do not let the excitement lull you into inaction. You might not have to pay for a C3PAO anymore, but you still have a compliance program to run, like it or not, and your obligation has not really changed.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;There is a wide gap between killing a payment for a certificate and killing your investment in real security. I will come back to that. But first, let me be fair to the decision itself. The delivery model was broken anyway, and it was broken in a way that was documented well before July.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Back in March, the Government Accountability Office published a report warning that DoD had never assessed whether the private sector could supply enough assessors to run the program. DoD concurred. So the government's own auditor said the capacity did not exist, and the department agreed in writing.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The numbers say the same thing. The SBA put more than a hundred thousand small firms into the Phase 2 pipeline against roughly a hundred approved assessors. It estimated the cost of a third party certification at close to $600,000 for a small company, and just under $400,000 even for a firm that only had to self assess. A shop doing four million dollars a year cannot carry a six figure compliance bill, and a hundred assessors cannot clear a hundred thousand companies this decade. The program was pricing out the exact small innovators it was supposed to protect, and in turn locking them out. So the suspension is really the arithmetic catching up with the policy. It was inevitable.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(71).png?width=729&amp;amp;height=449&amp;amp;name=image%20(71).png" width="729" height="449" alt="image (71)" style="height: auto; max-width: 100%; width: 729px;"&gt;&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;What always bothered me about CMMC&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;I see a real tension here. CMMC was trying to do two hard things at once. It wanted to verify that contractors were genuinely protecting sensitive data, because years of self-attestation had failed and adversaries had walked off with real program information. It also wanted to keep the industrial base wide enough to build what the country needs, including the small and nontraditional shops that have the technology but not the compliance infrastructure. At the scale the program demanded, those two goals ran straight into each other, and that is what broke. But that collision was about the machinery not the responsibility.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Strip away the abstraction and that responsibility lands on a person. Somewhere in your company a manager is responsible for protecting that data and has to sign their name to say it is handled. That was that manager's responsibility with CMMC in force. It is the same manager's responsibility with CMMC on hold. Lawyers call it a standard of care. On the floor it is just the person whose neck is on the line. CMMC never created that responsibility. It only graded it. And the grade is the only thing that changed.&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;You are the last set of eyes now&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;In January 2021, a Massachusetts defense contractor called MORSECORP told the government its NIST 800-171 score was 104, near the top of a scale that runs from -203 to 110. That score was wrong. They found out just how wrong a year later, when the company brought in an outside firm to run a gap analysis and the real number came back at -142. MORSE left the inflated 104 on the books and kept winning work on it. It did not correct the number until a federal subpoena forced the issue years later, and last year it paid 4.6 million dollars to settle the False Claims Act case that followed.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(72).png?width=731&amp;amp;height=343&amp;amp;name=image%20(72).png" width="731" height="343" alt="image (72)" style="height: auto; max-width: 100%; width: 731px;"&gt;&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Notice who paid that bill? The company that signed the number, and nobody else. And it was not blindsided. An outside firm had already told MORSE the real score. It buried that finding and left the inflated number in place. The assessment did its job. The company refused to listen, and the bill came due.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;That is what an outside look is really for; it tells you whether you are actually meeting the bar, in time to fix the gaps before you put your name behind the number. Phase 2 was about to make that outside assessment mandatory for everyone handling CUI. The suspension pulled that requirement, and DoD has ordered it stripped out of active contracts. The price for getting your security wrong did not get pulled with it.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;And the government auditor did not vanish along with the commercial one. DIBCAC still runs government led assessments, and the memo says those continue. For a manufacturer that means someone can still walk your floor and look at whether your business network is genuinely separated from your machine controllers, which a paper checklist was never going to catch anyway.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The Justice Department's cyber fraud effort is fully operational, and the incentives behind it are only getting stronger. The whistleblower who flagged MORSE collected $851,000, and the plaintiffs' bar now has a playbook for these cases. Crowell &amp;amp; Moring is already warning DOJ could turn toward false Phase 1 self-assessments next. Read that as the pressure heating up, not cooling down.&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;You cannot put this back in the box&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The primes spent the last five years building CMMC compliance into how they operate, and they are under the exact same rules you are. DFARS 7012 and the False Claims Act do not stop at the prime's front door. When a prime hands you CUI, your security becomes their exposure, because a breach at a sub, or a false attestation from one, lands on the prime that vouched for its supply chain. They need their subs secure to protect themselves, and regardless, no press release out of Washington is going to rewrite your subcontract.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The compliance standard is already heavily operationalized. Consider RTX. It bakes your CMMC status into its annual supplier registration process and will not issue a purchase order to a supplier handling CUI without it. Or Lockheed, which requires a green rating in its Exostar questionnaire as a condition of staying on the program. General Dynamics Mission Systems demands a minimum SPRS score of 88, no waivers. None of that is tied to the November date, and none of it moved this week. If you supply a major prime, your obligation this morning is the same as it was last week.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;So the compliance program still exists along with the mandate, and all that we've lost is the professional validation process. The prime is already pulling your NIST 800-171 SPRS score out of the system by CAGE code, and until now the plan was to use the C3PAO certificate as the clean outside stamp that told them your reported score was accurate and trustworthy. That stamp is now gone. What is left in their hands is self-reported: your SPRS score and whatever their own questionnaire tells them. The prime is still holding all of its own liability, and I am guessing that with the independent check pulled out from under them, they are not going to shrug and trust the honor system. I am thinking it is more likely that this pause only ups the scrutiny of the SPRS score, and that this is not the moment to be carrying a number you cannot back up.&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;Do not mistake a memo for a repeal&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Remember, this is just a pause. The rule itself is still on the books, codified in federal regulation, published last September and effective in November. A memo can stop the clock. Unwinding a final rule takes formal rulemaking, and that runs for months or years.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The last administration paused the first version of CMMC in 2021 for its own review. It came back as CMMC 2.0 with the same bones, and the contractors who tore their programs down spent the next three years catching up. My money says this returns in some form, probably leaner, quite possibly after the next election. And whatever it looks like in the end, there is a good chance it comes back less bureaucratic and more focused on real risk management. Whoever dismantles everything now is going to feel it later.&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;So what actually makes sense&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;Davies used a phrase in the memo that I would frame on a wall,&lt;span&gt; &lt;/span&gt;&lt;em&gt;"tangible cyber hygiene rather than bureaucratic red tape."&lt;/em&gt;&lt;span&gt; &lt;/span&gt;She is describing where the money should have been going all along. Look, I am not here to knock compliance. It has its place and the checkboxes matter. But in more than twenty years doing this work, I have watched plenty of smart CIOs confuse a passing audit with a true measure of their actual risk.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;So maybe you are miffed. You poured real effort into marching toward CMMC and the finish line just moved. None of it is wasted. You already know 800-171 cold from chasing that certificate. Point that same momentum at the framework itself. Test the controls regularly and model the realistic threats that target your enterprise specifically. Do that and you come out of this pause more secure than the certificate would ever have made you. And if the DoW changes its mind and a new certificate requirement lands on you, you will already be ready for it.&lt;/p&gt; 
&lt;h2 style="color: #0d1117; background-color: #ffffff;"&gt;The bottom line&lt;/h2&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;The certificate is on hold. What you owe when you hold government data has not moved an inch. That standard of care hasn't changed at all. All the pause really did was pull out the independent outside check that would have validated your attested score. You still sign the attestation. Now no one checks that number but you. So be careful how you reach it. They suspended the certificate. Nobody suspended the standard of care.&lt;/p&gt; 
&lt;p style="color: #2d3748; background-color: #ffffff;"&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/image%20(73).png?width=728&amp;amp;height=565&amp;amp;name=image%20(73).png" width="728" height="565" alt="image (73)" style="height: auto; max-width: 100%; width: 728px;"&gt;&lt;/p&gt; 
&lt;h2 style="color: #1a1a2e; background-color: #ffffff;"&gt;Sources&lt;/h2&gt; 
&lt;ul style="color: #1a1a2e; background-color: #ffffff;"&gt; 
 &lt;li style="color: #4a5568;"&gt;Department of War, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026 (war.gov)&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;DoW CIO Memorandum 26-P-1023, "CMMC Reform," July 13, 2026&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;U.S. SBA, "SBA Commends U.S. Department of War's Suspension of CMMC Phase II," July 13, 2026 (cost figures, assessor capacity)&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;GAO-26-107955, "Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation," March 12, 2026&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;U.S. DOJ, "Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations," March 26, 2025&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;Crowell &amp;amp; Moring LLP, "Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review," July 2026 (crowell.com)&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;Federal News Network, DefenseScoop, Breaking Defense, National Defense Magazine, coverage of July 13, 2026&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;32 CFR Part 170 (CMMC Program rule), Federal Register, October 15, 2024 (effective December 16, 2024)&lt;/li&gt; 
 &lt;li style="color: #4a5568;"&gt;DFARS 252.204-7021 (48 CFR CMMC acquisition rule), Federal Register, September 10, 2025 (effective November 10, 2025)&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="background-color: #f8fafc; color: #1a1a2e;"&gt;
 &amp;nbsp;
&lt;/div&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fcmmcs-third-party-assessments-are-paused.-the-standard-of-care-isnt&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Government Security</category>
      <category>Cyber Defense</category>
      <category>Compliance</category>
      <pubDate>Mon, 20 Jul 2026 21:02:58 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/cmmcs-third-party-assessments-are-paused.-the-standard-of-care-isnt</guid>
      <dc:date>2026-07-20T21:02:58Z</dc:date>
      <dc:creator>Denis Calderone</dc:creator>
    </item>
    <item>
      <title>The Training Tax</title>
      <link>https://suzulabs.com/suzu-labs-blog/the-training-tax</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/the-training-tax" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/Trainnig%20Tax%20Blog.png" alt="The Training Tax" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-weight: bold; color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;span style="font-weight: bold; color: #0d7d94;"&gt;At a Glance&lt;/span&gt;&lt;/p&gt;  
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Training is a one-time bill. Inference compounds.GPT-4 cost over $100M to train. Serving GPT-4o at ChatGPT-scale usage costs over $350M per month.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The crossover happens fast.At 100 million daily users, cumulative inference spend overtakes a $100M training budget in 9 days. At 10 million users, it takes 11 months.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;After one year at scale, inference owns the ledger.At ChatGPT-level usage on 100M DAU, 97.7% of total spend goes to serving. Training is a rounding error.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Price cuts cannot outrun user growth.Halving per-token cost doubles the crossover window. Doubling users cuts it in half. User growth wins that race.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Inference efficiency is the real moat.The lab that serves cheapest captures deployments. Training gets conference talks. Serving gets customers.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Training a frontier model costs nine figures. Serving it at ChatGPT scale costs nine figures every month. The AI industry tracks the first number because it makes headlines. The second number determines whether the product survives.&lt;br&gt;&lt;br&gt;Training is fundraising. Inference is unit economics.&lt;br&gt;&lt;br&gt;&lt;span style="font-weight: bold; font-size: 24px; color: #0d7d94;"&gt;The Headline Number&lt;/span&gt;&lt;br&gt;&lt;br&gt;Sam Altman told an MIT audience in April 2023 that GPT-4 cost more than $100 million to train. That figure became the reference point for every article about AI economics. Epoch AI, working from hardware amortization and energy data, estimated the final training run at $40 million, though their methodology notes individual estimates can vary by several-fold. Google's Gemini Ultra landed near $30 million on the same methodology.&lt;br&gt;&lt;br&gt;These numbers are real. They are also bounded. A training run ends. A serving bill compounds with every user on every request.&lt;br&gt;&lt;br&gt;A lab raises a funding round, rents a cluster, trains for months, and ships a model. The bill arrives once. Press releases quote it. Training cost is the number everyone knows.&lt;br&gt;&lt;br&gt;&lt;span style="font-weight: bold; font-size: 24px; color: #0d7d94;"&gt;The Number Nobody Tracks&lt;/span&gt;&lt;br&gt;&lt;br&gt;Inference is different. Every query burns GPU cycles. Daily active users multiply that burn by their session count.&lt;br&gt;&lt;br&gt;Training scales with ambition. Inference scales with success.&lt;br&gt;&lt;br&gt;We modeled the crossover point using July 2026 list API pricing from OpenAI, Anthropic, and Google. Our base scenario: five queries per user per day, 800 input tokens and 400 output tokens per query ($0.006 per query on GPT-4o). A ChatGPT-scale scenario uses 13 queries per user per day with 1,200 input and 600 output tokens ($0.009 per query), based on OpenAI's reported 2.5 billion prompts per day. We infer 193 million DAU by dividing that figure by 13 prompts per daily user.&lt;br&gt;&lt;br&gt;At 10 million DAU, GPT-4o inference at $2.50/$10.00 per million tokens crosses a $100 million training budget in 11.1 months. Monthly inference at that scale runs $9 million, or $0.90 per user. One million DAU pushes crossover past nine years.&lt;br&gt;&lt;br&gt;Scale changes everything.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/training_tax_crossover.png?width=1635&amp;amp;height=964&amp;amp;name=training_tax_crossover.png" width="1635" height="964" alt="training_tax_crossover" style="height: auto; max-width: 100%; width: 1635px;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;br&gt;At 100 million DAU under the ChatGPT-scale scenario ($0.009 per query), the $100 million training line falls in 9 days. Monthly inference exceeds $351 million. After 12 months, inference accounts for 97.7% of total spend: $100 million in training against $4.21 billion in serving costs.&lt;br&gt;&lt;br&gt;The math is transparent. Cost per query on GPT-4o at list rates: $0.006 in the base scenario, $0.009 in the ChatGPT-scale scenario, multiplied by daily queries, daily active users, and 30 days. List pricing overstates internal serving costs at labs running their own silicon, but the shape holds.&lt;br&gt;&lt;br&gt;Cut the per-token price in half and the 10M-DAU crossover moves from 11 months to 22. Double the user base and it drops to 5.5.&lt;br&gt;&lt;br&gt;&lt;span style="font-weight: bold; font-size: 24px; color: #0d7d94;"&gt;Why Inference Scales Differently&lt;/span&gt;&lt;br&gt;&lt;br&gt;Training behaves like a fixed cost per model generation. You set the parameter count, the data mix, and the compute budget. The bill is locked before the first token ships to a user.&lt;br&gt;&lt;br&gt;Inference is variable cost. Each GPT-4o user costs roughly $0.90 per month at list rates under our base scenario. At 100 million users, that is $90 million per month in serving costs alone.&lt;br&gt;&lt;br&gt;A startup can raise $50 million to train a competitive model. It cannot raise $50 million every month to serve one at a loss. OpenAI reported 900 million weekly active users in February 2026. At that scale and ChatGPT-level usage patterns, list-rate inference would exceed $650 million per month.&lt;br&gt;&lt;br&gt;Rising training budgets do not change the ratio. A $500 million training run at ChatGPT-scale usage on 100 million DAU still hits the crossover in six weeks. Training costs double with each model generation. User growth moves faster.&lt;br&gt;&lt;br&gt;the AI Economics series titled, &lt;em&gt;&lt;i&gt;&lt;a&gt;&lt;/a&gt;&lt;a href="https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment"&gt;&lt;/a&gt;&lt;a href="https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment"&gt;The Prescott Moment&lt;/a&gt;, &lt;/i&gt;&lt;/em&gt;established that commercial AI crossed from capability-constrained to compute-constrained.&amp;nbsp; The training tax is the other half of that shift.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/cost_structure_split.png?width=1334&amp;amp;height=814&amp;amp;name=cost_structure_split.png" width="1334" height="814" alt="cost_structure_split" style="height: auto; max-width: 100%; width: 1334px;"&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;At 10 million DAU, inference and training split roughly even after one year: 51.9% inference, 48.1% training on a $100 million budget. Below 1 million DAU, training still dominates the ledger. Above 100 million, inference takes 91.5% even in the conservative base scenario.&lt;br&gt;&lt;br&gt;The crossover window is narrow. Most successful deployments blow through it fast.&lt;br&gt;&lt;br&gt;&lt;span style="font-size: 24px; font-weight: bold; color: #0d7d94;"&gt;The Pricing War&lt;/span&gt;&lt;br&gt;&lt;br&gt;API pricing has dropped sharply since GPT-4 launched at $30/$60 per million tokens in 2023. GPT-4o now lists at $2.50/$10, GPT-4.1 at $2.00/$8, Claude Sonnet 5 at $3.00/$15 after its introductory period, Gemini 2.5 Pro at $1.25/$10 for standard-length prompts. Flash-tier models from Google and OpenAI have fallen below $0.20/$0.60.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://suzulabs.com/hs-fs/hubfs/inference_pricing_comparison.png?width=1334&amp;amp;height=814&amp;amp;name=inference_pricing_comparison.png" width="1334" height="814" alt="inference_pricing_comparison" style="height: auto; max-width: 100%; width: 1334px;"&gt;&lt;/p&gt; 
&lt;p&gt;Price cuts help. They do not repeal the scaling law. If query volume grows faster than per-token costs fall, total inference spend still rises.&lt;/p&gt; 
&lt;p&gt;A 50% price reduction doubles the DAU needed to hit the same crossover point. Doubling DAU cuts the crossover period in half. User growth wins that race at scale.&lt;/p&gt; 
&lt;p&gt;Provider competition compresses margins on the serving side. The lab that serves at the lowest cost per query captures the deployments that matter. Training efficiency gets conference talks. Inference efficiency gets customers.&lt;/p&gt; 
&lt;p&gt;Per-query cost on Claude Sonnet 5 at standard rates runs 40% higher than GPT-4o in our base scenario. Sonnet hits the $100 million crossover at 10M DAU in 7.9 months instead of 11.1.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-size: 24px; font-weight: bold; color: #0d7d94;"&gt;Who Pays the Tax&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;Labs that optimize only for training clusters are solving half the problem. The next competitive advantage is inference efficiency: quantization, speculative decoding, mixture-of-experts routing, distillation to preserve capability while cutting per-query compute. Meta open-sourced Llama so others would pay the serving bill. OpenAI ships GPT-4o mini because margin on inference volume beats margin on training prestige.&lt;/p&gt; 
&lt;p&gt;Inflection AI raised $1.3 billion and shipped Pi, a consumer chatbot. Within a year, its CEO and co-founder moved to Microsoft and the company pivoted to enterprise APIs. Building the model was the fundraising story. Surviving the inference bill was the business story nobody wrote.&lt;/p&gt; 
&lt;p&gt;Training is fundraising. Inference is unit economics.&lt;/p&gt; 
&lt;p&gt;A model that costs $100 million to train and $350 million per month to serve needs massive subscription revenue or a path to cheaper inference within weeks of launch. At nine-figure scale, there is no third option. Article 3, &lt;em&gt;&lt;i&gt;The Economics of AI Deployment&lt;/i&gt;&lt;/em&gt;, which is next in the AI Economics series, takes up who can actually afford to run these models.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment"&gt;The Prescott Moment&lt;/a&gt; identified the bottleneck: compute. The training tax pins down where that compute budget burns. Training cost determines who enters the frontier race. At $9 million per month for every 10 million users on GPT-4o, inference cost determines who stays.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-size: 20px; font-weight: bold; color: #0d7d94;"&gt;Sources&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://developers.openai.com/api/docs/pricing"&gt;OpenAI API Pricing&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://platform.claude.com/docs/en/about-claude/pricing"&gt;Anthropic Claude Pricing&amp;nbsp;&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://ai.google.dev/gemini-api/docs/pricing"&gt;Google Gemini API Pricing&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.wired.com/story/openai-ceo-sam-altman-the-age-of-giant-ai-models-is-already-over/"&gt;Wired: Sam Altman on GPT-4 training cost&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://arxiv.org/html/2405.21015v2"&gt;Epoch AI: The rising costs of training frontier AI models&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://openai.com/index/scaling-ai-for-everyone/"&gt;OpenAI: Scaling AI for everyone&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://techcrunch.com/2025/07/21/chatgpt-users-send-2-5-billion-prompts-a-day/"&gt;TechCrunch: ChatGPT users send 2.5 billion prompts a day&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.reuters.com/technology/artificial-intelligence/openai-closes-122-billion-funding-round-2026-02-27/"&gt;Reuters: OpenAI $110B funding round&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.bloomberg.com/news/articles/2024-03-19/microsoft-hires-inflection-co-founders-to-run-consumer-ai"&gt;Bloomberg: Inflection AI leadership move to Microsoft&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fthe-training-tax&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI Economics</category>
      <category>Interference-Costs</category>
      <category>Training-Costs</category>
      <category>Deployment</category>
      <pubDate>Mon, 20 Jul 2026 19:50:11 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/the-training-tax</guid>
      <dc:date>2026-07-20T19:50:11Z</dc:date>
      <dc:creator>Jacob Krell</dc:creator>
    </item>
    <item>
      <title>Why Mobile Applications Need Real Penetration Testing</title>
      <link>https://suzulabs.com/suzu-labs-blog/why-mobile-applications-need-real-penetration-testing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/why-mobile-applications-need-real-penetration-testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/ChatGPT%20Image%20Jul%2021%2c%202026%2c%2012_44_14%20PM.png" alt="Why Mobile Applications Need Real Penetration Testing" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Mobile applications have become a primary interface between organizations and their customers, handling everything from authentication and payments to sensitive personal and business data. While strong backend security is critical, attackers often target the mobile client itself, looking for opportunities to reverse engineer the application, bypass security controls, or abuse business logic in ways that expose sensitive functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mobile applications have become a primary interface between organizations and their customers, handling everything from authentication and payments to sensitive personal and business data. While strong backend security is critical, attackers often target the mobile client itself, looking for opportunities to reverse engineer the application, bypass security controls, or abuse business logic in ways that expose sensitive functionality.&lt;/p&gt; 
&lt;p&gt;At Suzu Labs, our mobile penetration testing goes beyond automated scans and static code analysis. We perform hands-on security assessments using techniques such as reverse engineering, runtime tampering, client-side manipulation, and business logic testing to understand how a determined attacker could interact with the application. This allows us to identify weaknesses including insecure local data storage, hardcoded credentials, insufficient certificate validation, weak jailbreak or root detection, exposed API endpoints, and client-side trust assumptions that can be exploited to gain unauthorized access.&lt;/p&gt; 
&lt;p&gt;We also evaluate how the mobile application interacts with its backend APIs and cloud services, validating whether client-side protections can be bypassed to escalate privileges, manipulate transactions, or access data that should remain protected. Rather than simply reporting isolated vulnerabilities, we focus on demonstrating realistic attack paths that show the potential business impact of each finding.&lt;/p&gt; 
&lt;p&gt;By testing mobile applications from an attacker's perspective, organizations gain a clear understanding of where real risk exists and how to remediate the issues that matter most. The result is a more resilient mobile application that protects users, secures sensitive data, and withstands the techniques used in modern mobile attacks.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fwhy-mobile-applications-need-real-penetration-testing&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity</category>
      <category>Penetration Testing</category>
      <category>Mobile Pentesting</category>
      <pubDate>Mon, 20 Jul 2026 15:45:00 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/why-mobile-applications-need-real-penetration-testing</guid>
      <dc:date>2026-07-20T15:45:00Z</dc:date>
      <dc:creator>Suzu Labs</dc:creator>
    </item>
    <item>
      <title>Cloud Security Means More Than Securing the Cloud</title>
      <link>https://suzulabs.com/suzu-labs-blog/cloud-security-means-more-than-securing-the-cloud</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/cloud-security-means-more-than-securing-the-cloud" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/ChatGPT%20Image%20Jul%2021%2c%202026%2c%2012_20_35%20PM.png" alt="Cloud Security Means More Than Securing the Cloud" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;p&gt;As organizations connect more IoT devices to cloud platforms, the attack surface expands well beyond the device itself. APIs, cloud identities, storage services, and backend management platforms all become potential entry points for attackers. A single misconfigured permission or exposed API can allow an attacker to escalate privileges, access sensitive data, or pivot between cloud resources and connected devices.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;As organizations connect more IoT devices to cloud platforms, the attack surface expands well beyond the device itself. APIs, cloud identities, storage services, and backend management platforms all become potential entry points for attackers. A single misconfigured permission or exposed API can allow an attacker to escalate privileges, access sensitive data, or pivot between cloud resources and connected devices.&lt;/p&gt; 
&lt;p&gt;At Suzu Labs, we test cloud environments the way real attackers do. Rather than stopping at vulnerability scans, we evaluate how APIs, identity controls, cloud permissions, and IoT management platforms interact. We look for privilege escalation opportunities, insecure trust relationships, overly permissive IAM roles, and lateral movement paths that could allow a compromise of one device or service to spread throughout an environment.&lt;/p&gt; 
&lt;p&gt;Modern cloud security isn't just about protecting infrastructure, it's about understanding how every connected component can be abused together. By validating real attack paths across cloud platforms and IoT ecosystems, organizations gain a clear understanding of the risks that matter most and the remediation steps that will have the greatest security impact.&lt;/p&gt;   
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fcloud-security-means-more-than-securing-the-cloud&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Penetration Testing</category>
      <category>IoT Pentesting</category>
      <category>Cloud Security</category>
      <pubDate>Thu, 16 Jul 2026 16:30:00 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/cloud-security-means-more-than-securing-the-cloud</guid>
      <dc:date>2026-07-16T16:30:00Z</dc:date>
      <dc:creator>Suzu Labs</dc:creator>
    </item>
    <item>
      <title>Third-Party Risks: When Trusted Connections Become Attack Paths</title>
      <link>https://suzulabs.com/suzu-labs-blog/third-party-risks-when-trusted-connections-become-attack-paths</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://suzulabs.com/suzu-labs-blog/third-party-risks-when-trusted-connections-become-attack-paths" title="" class="hs-featured-image-link"&gt; &lt;img src="https://suzulabs.com/hubfs/ChatGPT%20Image%20Jul%2021%2c%202026%2c%2001_18_26%20PM.png" alt="Third-Party Risks: When Trusted Connections Become Attack Paths" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Modern applications rarely operate alone. They rely on API gateways, webhooks, cloud services, SaaS platforms, and partner integrations to exchange data and automate critical business processes. These trusted connections accelerate business, but they also create additional attack surfaces that are often overlooked during traditional security assessments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Modern applications rarely operate alone. They rely on API gateways, webhooks, cloud services, SaaS platforms, and partner integrations to exchange data and automate critical business processes. These trusted connections accelerate business, but they also create additional attack surfaces that are often overlooked during traditional security assessments.&lt;/p&gt; 
&lt;p&gt;Attackers know that third-party integrations frequently operate on implicit trust. Shared API keys, long-lived credentials, overly permissive access controls, insecure webhook validation, and misconfigured API gateways can all provide opportunities to bypass security controls. In many real-world incidents, a trusted integration becomes the easiest path to sensitive systems because it's assumed to be secure by default.&lt;/p&gt; 
&lt;p&gt;At Suzu Labs, we test the trust relationships that exist between your applications and the external services they depend on. We assess API gateways, webhooks, partner connections, and machine-to-machine authentication to identify where trust boundaries can be abused. Our testing validates authentication and authorization controls, examines how shared secrets are protected, and evaluates whether attackers could leverage one trusted connection to gain broader access or escalate privileges.&lt;/p&gt; 
&lt;p&gt;Rather than stopping at configuration reviews, we simulate realistic attack paths to understand the real-world impact of these integrations. We look for opportunities to chain weaknesses together, abuse excessive permissions, manipulate webhook payloads, or pivot through trusted services into more sensitive parts of your environment.&lt;/p&gt; 
&lt;p&gt;As organizations continue to build increasingly interconnected ecosystems, third-party security is no longer optional. Regular testing of partner integrations helps ensure that the systems you trust every day don't become the attack path someone else uses to compromise your business.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=243748608&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsuzulabs.com%2Fsuzu-labs-blog%2Fthird-party-risks-when-trusted-connections-become-attack-paths&amp;amp;bu=https%253A%252F%252Fsuzulabs.com%252Fsuzu-labs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Penetration Testing</category>
      <category>Third-party vendor risk</category>
      <category>third party breach risk</category>
      <pubDate>Thu, 16 Jul 2026 15:30:00 GMT</pubDate>
      <guid>https://suzulabs.com/suzu-labs-blog/third-party-risks-when-trusted-connections-become-attack-paths</guid>
      <dc:date>2026-07-16T15:30:00Z</dc:date>
      <dc:creator>Suzu Labs</dc:creator>
    </item>
  </channel>
</rss>
