Galactic Research: Articles & Insights
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
AI Security
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Perfect AI Guardrails Are Impossible. That's Not an Excuse for Ignoring Them.

What a NIST Mathematician Proved, Why the Internet Got it Wrong, and What Your AI Security Program Should Look Like Years ago, running an MSSP, I had a vendor pitch us a next-gen firewall on a single promise: one hundred ...
Threat Intelligence
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 13th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 6th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
Companies Spending More On Tech Services Due To Remote Work
The Coupa Business Spend Index (BSI) has been volatile over the past several months as the pandemic shredded business confidence and sent budgets into a downward spiral. Some business spending has barely ...
Ransomware After Removing A Virus
Maybe this story is familiar to you (or more likely someone on your team)… I was working with a hospital ...
Feature Similar To iPhone Airdrop Was Added To Android
Apple users are almost certainly familiar with the Airdrop feature, which allows content to be shared between two iPhones that are in close proximity to each other. Recently, Google announced the rollout ...
Trickbot Adds New Trick Linux Malware
Trickbot is about as bad as they come in the world of malware. Originally a malware strain from the Windows ecosystem, security professionals have recently found samples of the code in the ...
This New Malware Added An Email Attachment Stealer
Emotet's massive botnet was dormant for several months, but on July 17th, 2020, it suddenly rumbled back to life. It started spewing out massive numbers of phishing emails aimed at installing Trickbot ...
Online Shoppers Are Seeing An Increase In Scams
Recently, the FBI issued an advisory warning about a sharp increase in the number of reported victims of online shopping scams. According to data compiled by the FTC, the last few months ...
Popular Interior Design Website Has Breach Of User Accounts
The most recent company to have fallen victim to hackers is Havenly. They are a US-based interior design firm with an interactive website that allows users to get interior design help from ...
Meetup Website Has Patched Vulnerability Open To Hackers
Recently, security researchers at Checkmarx discovered a pair of serious vulnerabilities in the popular online meeting website Meetup. According to the researchers, a hacker could combine cross-site scripting (XSS) with cross-site request ...
Attackers Are Taking Aim At O365
At this point, Microsoft’s Office 365 has become one of the most common business email platforms. Subsequently, as discussed at Blackhat last week, it is becoming a hot target for criminals as ...
Cisco Data Center Manager Software Users Should Patch Immediately
Do you use Cisco's Data Center Manager Software? If so, be advised that the company recently issued an advisory concerning a serious security flaw. The advisory reads, in part, as follows: "The ...
New Netflix Payment Phishing Emails Appear Legitimate
Do you have a Netflix account? If so, you're certainly not alone. Since the start of the pandemic, the company has experienced unprecedented growth, and is now the video streaming service of ...
Trickbot Malware Went Into Hiding And Now It’s Back
For more than five months, the internet breathed a collective sigh of relief as one of the most notorious strains of malware, Emotet, went dark and ceased all activity. It was as ...


