Skip to content

Topic

Insider Threat

A security risk from employees, contractors, or other trusted individuals who misuse legitimate access to steal data, sabotage systems, or aid attackers.

Current stories

security7 publishers

Army soldier who extorted AT&T using Snowflake logins without MFA gets 70 months

Army soldier Cameron Wagenius got 70 months in prison for extorting AT&T with call records taken from Snowflake accounts that lacked MFA. His group got in with exposed credentials alone, and AT&T's $370,000 ransom did not stop the leaks that followed.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 59%
Investor
Investor 19%

Reality

Evidence82
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence78
invest1 publisher

Fed's watchdog ties a year-long unresolved removal of classified FOMC files to unclear division roles

Fed's inspector general found that unclear roles among Fed divisions left a former staffer's removal of classified FOMC files unresolved for over a year. The Fed says its fix for escalating such alerts arrives by the first quarter of 2027, and part of the removed material has not been retrieved.

Reality

Evidence68
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence62
security1 publisher

Prompt injection recruits a fully credentialed agent

Pillar Security's Dor Sarig argues the non-human identity buildout answers who an agent is rather than what it does, and cites an internal agent any Slack message could trigger across a thousand private repositories.

Publishers:scworld.com

Reality

Evidence24
Adoption18
Hype gap+28
Incentives86
Confidence52