Show notes
This episode analyzes the growing divide between regulatory compliance and actual operational resilience, highlighted by new IO research showing that 87% of cybersecurity managers believe speed-focused certification programs actually increase business risk. We examine how automated "tick-box" exercises for standards like ISO 27001 can create a false sense of security while leaving critical gaps in security posture. The briefing also covers a significant shift in software supply chain security, as GitHub updates its official checkout action to block "pwn request" patterns that have plagued CI/CD workflows. We dive into the "Cordyceps" research from Novee, which identified hundreds of vulnerable repositories at major firms like Microsoft and Google. Finally, we look at the Department of Justice's seizure of cloud infrastructure belonging to the HuiOne Group, a Cambodia-based conglomerate that facilitated over $31 billion in illicit cryptocurrency transactions for Southeast Asian scam centers. These stories underscore the necessity of human oversight in an increasingly automated threat landscape.



