CYBER DESK · HONG KONG · WEEKLY · ARCHIVE

Previous Columns

6 columns
May 19, 2026
CISA's Contractor Left AWS Keys on GitHub
Two of this week's most instructive breaches trace to credentials in version control, not zero-days; one contractor works for the agency that mandates US federal remediation timelines.
Kai Tanner
May 16, 2026
The Patch Window Closed Before It Opened
Two CVSS 10 Cisco SD-WAN bugs exploited in five months, plus a JavaScript supply chain burning two OpenAI developer devices, argues that the exploitation window has structurally closed.
Kai Tanner
May 12, 2026
AI-Generated Zero-Day Rewrites the Patch Calculus
Google's confirmation of an AI-built zero-day in criminal deployment is a measurement, not a milestone: the exploitation window is now shorter than any current TRM timeline assumes.
Kai Tanner
May 5, 2026
AI on the Threat Feed, Unabsorbed
Anthropic's Mythos appearing on institutional threat registries forces a question that procurement frameworks and cyber insurance policies were not built to answer.
Kai Tanner
May 5, 2026
Weapons Language and the Institutional Lag Behind It
Treasury's 'nuclear weapon' framing for AI in finance is institutional acknowledgment that the attack surface has changed faster than the governance structures meant to contain it.
Kai Tanner
April 28, 2026
The Patch Queue Can't Run at Discovery Speed
Frontier AI is compressing the exploit window while supply chain attacks compromise the very tools defenders use to close it.
Kai Tanner