1. Home
  2. Worth reading
ReadingMostly not ours

Worth reading.

Advisories, breach reports and industry analysis about what is connected and what nobody can see. Almost none of it is written by us, and where we quote somebody it is their words, not our summary of them.

  • Verbatim 4
  • Breach 4
  • OT 3
  • Vendor analysis 3
  • CISA 2
  • Primary source 2
  • AV Integrators 2
  • Industry analysis 1
  • Visibility 1
  • Federal 1

2026

insidehighered.com

Instructure Pays Ransom to Canvas Hackers

Canvas LMS breach affected approximately 275 million users across more than 8,800 higher-education institutions. Canvas serves roughly 41 percent of higher-education institutions across North America. Instructure paid the ShinyHunters ransom; the compromised data was returned and reportedly destroyed. Every institution that uses Canvas inherited exposure from a single-vendor compromise it had no local ability to detect.

  • Breach
oodaloop.com

Hardware as the Hidden Battlefield

Field deployments of chip-level Independent Verification and Validation (IV&V) technology have identified substantial hardware-level anomalies in 53% of the tested equipment.

Trent R. Teyema, DSc & David Bray, PhD, oodaloop.com
  • Industry analysis
  • Verbatim
insidehighered.com

'PAY OR LEAK': Hackers Target Big Higher Ed Vendor

Initial disclosure of the Canvas LMS compromise. ShinyHunters claimed responsibility and demanded payment by May 12. The first incident statement on May 1 was followed by a second compromise on May 7 in which the login page itself was replaced with a ransomware message. Higher-ed institutions inherited the exposure without any local opportunity to detect or contain it.

  • Breach
statnews.com

Health care is not ready for the new era of AI-enabled cyberattacks

Bugs don't go unpatched because no one can find them. They go unpatched because no one is being paid to patch them fast enough." (Marcus Hutchins, security researcher) And: "A hospital can't push a patch to electronic health records any more than a homeowner can reinforce a levee owned by the county that may break in a hurricane.

Andrea Downing, STAT News, statnews.com
  • Verbatim
lansweeper.com

Asset Visibility in Cybersecurity: Why You Can't Secure What You Can't See

Asset visibility is positioned as the foundation of cybersecurity. Every security control, policy, and response action depends on accurate knowledge of which assets exist, how they are configured, and what they are exposed to. The article cites the average cost of a data breach now exceeding $4.4 million globally and over $10 million in the U.S.

  • Vendor analysis
  • Visibility
federalnewsnetwork.com

Visibility is the only way to fix the public's growing security debt

78 percent of public-sector organizations carry significant "security debt," meaning software with flaws that remain unpatched for more than a year. The public-sector backlog is now measured in years, not weeks. Visibility is the load-bearing prerequisite for any prioritization at all.

  • Federal
federalnewsnetwork.com

NIST cyber center to launch OT 'visibility' project

NIST's National Cybersecurity Center of Excellence is launching an operational-technology visibility project. OT inventory and asset identification are named as the load-bearing prerequisites for the rest of the OT-security stack. The federal cyber-policy stack is converging on inventory-first as the default expectation.

  • OT
comparitech.com

Healthcare ransomware roundup: Q1 2026 stats on attacks, ransoms, and data breaches

Q1 2026 healthcare ransomware roundup: 201 ransomware attacks were recorded in the healthcare sector during Q1 2026, of which 120 hit hospitals, clinics, and healthcare providers directly. More than 60 percent of confirmed healthcare breaches in 2025 involved ransomware (up from 34 percent in 2021). Fewer than 30 percent of health systems have deployed any dedicated solution for discovering and monitoring their connected device population.

  • Healthcare
securityboulevard.com

1.2 Million Bank Accounts Exposed in Financial Systems Breach

Q1 2026 financial-services breach exposing roughly 1.2 million bank accounts. Coverage in this period continues a pattern: NYDFS now requires institutions to attest annually that they maintain accurate IT asset inventories with owner, location, sensitivity, vendor support expiration, and recovery time objectives for every asset. The first annual certification was due April 15, 2026. Penalties up to $250,000 per day for ongoing non-compliance.

  • Breach
avnetwork.com

ISE 2026 Launches Inaugural CyberSecurity Summit

AVIXA named cybersecurity the number-one AV industry trend for 2026. ISE 2026 launched the first dedicated AV CyberSecurity Summit. The pro-AV industry has officially acknowledged what enterprise security teams have been discovering for years: AV infrastructure is now a serious security domain, and treating it otherwise creates measurable organizational risk.

  • AV Integrators
helpnetsecurity.com

Hospitals are drowning in threats they can't triage

Hospitals run thousands of connected endpoints, many unmanaged, many legacy, many without modern authentication. The Nippon Medical School Musashi Kosugi Hospital incident (February 2026, claimed by NetRunner) affected 131,700 people and is one of several real-world demonstrations of how unmanaged-device exposure becomes a clinical-operations crisis.

  • Breach
vicom-corp.com

Your Conference Room Is an Attack Surface: Zero-Trust Security for Networked AV Systems

Networked AV devices appear with increasing frequency in post-breach forensic reports as the initial point of entry or the lateral-movement path. Control rooms, conferencing platforms, digital signage, smart buildings, event venues. The organizational disconnect between AV and IT teams is the actual exposure: pure AV integrators stop at the equipment, never the network switch.

  • Vendor analysis
  • AV Integrators
digital.securitysystemsnews.com

Security Systems News, digital issue

If you can't identify what's on the network, you can't secure it. Hope isn't a strategy. It's not if you get hacked — it's when.

  • Verbatim
sherlockforensics.com

Cyber Insurance Renewal Checklist 2026 — What Insurers Want

2026 cyber-insurance renewal applications now run 12 to 20 pages with line-by-line control questions. Underwriting has moved from questionnaire-based to evidence-based. Documented controls move premiums by 20 to 40 percent in either direction. Asset inventory is one of the gating questions. Missing basic controls now triggers claim denials and coverage exclusions, not just premium increases.

  • Vendor analysis
  • Insurance

2024

cisa.gov

PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure — CISA Advisory AA24-038A

The original Volt Typhoon advisory: PRC actors are pre-positioning on IT networks to enable lateral movement to OT assets to disrupt functions during a potential geopolitical contingency. Cited continuously through the 2026 follow-up advisories. Some U.S. critical-infrastructure targets had been compromised for as long as five years before detection.

  • CISA
  • Primary source
  • OT

If any of that sounded like your estate

The two pages that answer it with numbers instead of argument.

Links go to the publisher. We get nothing for them, and a link is not an endorsement of whoever published it, only of the point being made.