MalwareInside the fourth wave of the Shai-Hulud npm wormBrad LaPorteAugust 20, 2026The signed packages were authentic – but that’s precisely the problem: the provenance lied.
Patch/Configuration ManagementWhy CISA’s 3-day patching mandate misses the pointBrad LaPorteJune 15, 2026Ai has broken our patching system – and here’s what needs to change.
Governance, Risk and ComplianceWhy the nation needs a more proactive CISABrad LaPorteOctober 7, 2025CISA must evolve from a bearer of bad news to a cornerstone of national cyber resilience.