Galactic Research: Articles & Insights
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
AI Security
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Perfect AI Guardrails Are Impossible. That's Not an Excuse for Ignoring Them.

What a NIST Mathematician Proved, Why the Internet Got it Wrong, and What Your AI Security Program Should Look Like Years ago, running an MSSP, I had a vendor pitch us a next-gen firewall on a single promise: one hundred ...
Threat Intelligence
Threat Thursday: August 13th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 6th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: July 30th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. Every Thursday we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
Windows Turned On Default Blocking For Potentially Unwanted Apps
Microsoft made a small but significant change to Windows 10 recently as it relates to PUAs (Potentially Unwanted Apps). It wasn't something that got a lot of press but it's a change ...
Google May Phase Out Secure Lock Icon For Websites
Google has had a long history of taking steps to make the web more secure for everyone. One of their early moves involved warning users via popup box when they surfed their ...
This Malware Can Take Control Of Facebook Accounts
Do you have a Facebook account? Even if it has been a while since you last logged on there is a new threat you should be aware of. A new strain of ...
Hackers Are Pretending To be Chipotle In Poisoned Emails
Hackers Are Pretending To be Chipotle In Poisoned Emails Chipotle recently reported that an account used by their company's marketing department had been hacked. A currently active campaign is underway leveraging this ...
New Mac Device Malware Is Bypassing Apple Security
Apple is generally very good about providing its users with a safe and secure computing environment. For many years the company was able to rightly claim that Microsoft had a far worse ...
Microsoft Teams Fend Off Phishing Attacks With Link Protection
Microsoft Defender has long included "Safe Links" protection as part of its overall function. The company recently announced that it would be extending Safe Link functionality so that it provides protection from ...
Improve Your Security By Taking The Offense
Last week was a whirlwind of cybersecurity. Outside the routine investigations into updates to the VSS, PrintNighmare, or M365 phishing events (all indicative of ...
Latest Security Update For Apple Devices Is Critical
Do you have an Apple device? If so then you should be aware that the company recently issued an OS update that includes Macs, iPads, and iPhones. You'll want to update to ...
Google Improving Security And Transparency For Android Apps
Google recently announced some additional details relating to their "Safety Section" feature of the Google Play store. This is part of an ongoing effort to make the Play Store a safer and ...
Your Kindle EBook May Lose Partial Functionality Soon
Do you own an older Amazon Kindle? Older Kindles utilize 3G internet connectivity protocols but mobile carriers are currently racing to upgrade their networks to 4G/5G. Older devices that only have a ...
Malware Named Xloader Targeting Macs And Stealing Information
XLoader is a newly discovered strain of malware designed to infect systems running macOS. This new strain was built from a malware strain called FormBook which was designed to steal passwords from ...
Some Older Printer Drivers Are Vulnerable To Hackers
SentinelOne recently published a report that revealed a previously undiscovered security flaw found in a wide range of printers that include printers manufactured by Samsung, Xerox, and HP. The bug is being ...


