Jack Poller

Founder & Principal Analyst, Paradigm Technica, covering Security, Cloud, and AI; former marketer, SW & HW Eng; Firearms Instructor & FFL, photographer, auto racer

2026-01-16

The ServiceNow 'BodySnatcher' vulnerability (CVE-2025-12420) shows why AI's race to market is a security disaster. Unauthenticated attackers hijacking AI agents to bypass MFA? This is what happens when we ship AI without proper security. My latest: securityboulevard.com/2026/01/

2025-12-29

Attackers see your network as a connected graph. You see disconnected alerts. That's why you're losing.

Microsoft Sentinel's AI librarian changes everything—from natural language queries to real-time attack disruption.

The SOC revolution: paradigmtechnica.com/2025/12/2

#cybersecurity #AI #SOC #TFDx

2025-12-22

Attackers see your network as a web of opportunities. You see disconnected silos.

Microsoft Sentinel's Attack Graph finally gives defenders the same view hackers have always had.

New blog on why graph thinking changes everything 👇
paradigmtechnica.com/2025/12/2

2025-12-16

Identity fraudsters found the weak spot: attack the chip, disable digital verification, claim it got damaged in my pocket.
HINT's solution is almost too simple: make the chip visible. Attacks leave cracks, burns, blisters anyone can see.
Low-tech answer to high-tech threat. securityboulevard.com/2025/12/

2025-12-16

Attackers exploit new vulnerabilities in 5 days. Your monthly patch cycle takes 30.
The math doesn't work anymore. Traditional vulnerability management is broken.
Continuous exposure management isn't optional—it's survival.
paradigmtechnica.com/2025/12/1

2025-12-11

New Op-Ed: The $10B Blind Spot—How OWASP's Top 10 Legitimizes Agent Insecurity
MCP's optional auth is quicksand for AI agents.
Attribution gaps? Token bombs? We need to burn it down & build mandatory Zero Trust identities

Read: paradigmtechnica.com/2025/12/1
#AISecurity #OWASP #CyberSec

2025-12-10

🚨 New Op-ed: Gartner's AI Browser Ban: Rearranging Deck Chairs on the Titanic
Banning AI browsers won't work—agentic AI is already in Microsoft 365, Slack & Zoom. The threat isn't the browser, it's the agents. You can't ban the future. Secure it.
securityboulevard.com/2025/12/

2025-12-08

RE: floss.social/@gisgeek/11567906

@gisgeek brings up some interesting and salient points about FOSS.

Check it out!

Jack Poller boosted:
Francesco P Lovergine :debian:gisgeek@floss.social
2025-12-08

A brief post inspired by a recent @poller post, about FOSS at a dead end for security.

lovergine.com/too-many-eyes-or

#foss #security #governance #dev

2025-12-04

AI safety ≠ AI security, and confusing them leaves you vulnerable on multiple fronts.
Safety = keeping your model ethical
Security = protecting systems from attackers
Your AI can be "safe" yet catastrophically insecure (or vice-versa).

Learn more: paradigmtechnica.com/2025/12/0

2025-12-03

@Epic_Null Microsoft does bear some responsibility.

But recognize that NPM was born in 2010, capitalized in 2014, acquired by Github (Microsoft) in 2020.

So for the first 10 years of its life, it wasn't owned by Microsoft and it suffered from the all-too-common SOP of bolting security on as an afterthought.

And that's the major issue *I* am discussing: We -- as a community -- must focus on designing security from day 0.

2025-12-03

@Epic_Null Yes, you're correct: NPM's core design is deeply flawed.

And that's my point. It's yet another open-source project built without any concern for security.

In the interest of space, I decided not to discuss the plethora of other open source compromises, such as the XZ / openSSH attack.

2025-12-03

@McNeely unfortunately, you're probably right, which is depressing.

2025-12-03

@greem fixed, thanks

2025-12-03

@gisgeek should be fixed now.

Thanks for letting me know.

2025-12-03

The "many eyes" myth is dead. Shai-Hulud, S1ngularity, and other attacks prove open source needs dedicated security teams, not just volunteers. AI-powered attackers are winning. Time to build something better.
Read my take here:
paradigmtechnica.com/2025/12/0
#opensource #security

2025-12-02

🔐 In the AI Era, Resilience Determines Who Leads and Who Falls Behind

AI amplifies everything, including failure.

My latest article explores why AI resilience is different and what it takes to turn your greatest risk into sustainable advantage.

linkedin.com/pulse/building-ai

#CommvaultShift

2025-11-25

Tycoon 2FA proves legacy MFA is dead!

The fix isn't harder passwords. It's hardware-backed cryptographic auth: no phishing or proxies.

Move beyond "something you know" to "something attackers can never steal."
🔐 Full analysis:
securityboulevard.com/2025/11/
#Cybersecurity #MFA #FIDO2 #ZeroTrust #InfoSec

2025-11-18

The central question for every enterprise leader in 2025:
How fast can you recover when (not if) a breach happens?

@Commvault Cloud Unity—announced at Commvault Shift—is redefining AI resilience.

My full breakdown 👇
linkedin.com/pulse/dawn-digita

#commvaultshift

2025-11-18

80% of production AI models fall to adversarial attacks. Traditional defenses can't keep up.

AI-orchestrated attacks—reconnaissance, exploit generation, credential harvesting, lateral movement, all at machine speed—are real and commercialized.

This changes everything: securityboulevard.com/2025/11/

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst