Galactic Research: Articles & Insights
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
AI Security
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Perfect AI Guardrails Are Impossible. That's Not an Excuse for Ignoring Them.

What a NIST Mathematician Proved, Why the Internet Got it Wrong, and What Your AI Security Program Should Look Like Years ago, running an MSSP, I had a vendor pitch us a next-gen firewall on a single promise: one hundred ...
Threat Intelligence
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 13th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 6th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
Chromebook Users Will Get New Tools And Features Soon
Do you own a Chromebook? If so, be aware that version 100 of the Chrome OS and Chrome Browser boasts a new launcher. Simply press the "Everything" button which is located on ...
Mobile Devices Connected To Windows Known As Phone Link
Microsoft recently announced that it was doing a bit of re-branding. The company's apps that connect Android and iPhones to your Windows PC were formally called "Your Phone." Under the new re-naming scheme, ...
vCSO: CISSP NOT Required
If you have ample experience, are interested in on-going training, looking to educate your client community and protect users, a CISSP is ...
Microsoft Help Files Are Being Used To Distribute This Spyware
Diana Lopera is a researcher for Trustwave Cybersecurity and has stumbled across something that's one part interesting and one part disturbing. Apparently, a group of hackers are trying a new approach to ...
Outlook Having PDF Preview Issues With Microsoft PowerToys
Do you use Microsoft PowerToys? If you're not sure what that is then you probably don't. If you're curious, Microsoft has an open-source set of tools called PowerToys which is designed to ...
New GIMMICK Malware Targets MacOS Users
If you follow the global threat landscape closely, then you may already be aware of a notorious Chinese hacking collective known as "Storm Cloud." What few people know is that this group seems ...
Data Breach Announced At Popular Photo Site Shutterfly
Online photography platform Shutterfly is the latest high-profile company to fall victim to a hacking attack. The company recently disclosed that in December of last year (2021) they were targeted by the ...
Fake Work From Home Opportunities Are Phishing For Data
It's no secret that the pandemic changed the way much of the world works. Tens of millions of people are now working from home with millions more eyeing that as a very ...
A Disguised Windows License Activator May Actually Be Malware
People who are in the habit of pirating movies and software have something new to worry about. It seems hackers have begun targeting at least some of them with a ubiquitous form ...
Is Permission Creep Keeping You Vulnerable?
Have you ever gotten that phone call? You know, THE phone call when you least expect it. Where one ...
Google Play Store Is Seeing More Trojan Style Malware
A security researcher who goes by the name "Dr. Web" has been tracking a suspicious increase in Trojan infiltration emanating from the Google Play Store. It is not currently known whether a ...
Automotive Part Maker Denso Is Latest To Have Data Breached
The automotive parts giant named DENSO is the latest corporation to fall victim to a hacking attack. The company has offices all over the world and supplies parts to brands including General ...


