Galactic Research: Articles & Insights
Threat Thursday: September 3rd, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
AI Security
Four Controls for AI Tools That Can't Defend Themselves

A weather plugin, a stolen conversation, and the case for enforcing security outside the model I recently spent an afternoon on a public challenge range, one of those practice environments security researchers use to test attacks safely against a deliberately ...
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Threat Intelligence
Threat Thursday: September 3rd, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 27th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
Notepad++ Compromise: What you need to know
The recent Notepad++ compromise should make you pause for a moment because the Chrysalis backdoor is exactly the type of malware those of in the industry lose sleep over. Rapid7’s write-up on the Chrysalis backdoor is not alarming because it ...
The New Frontier: Securities Class Actions Triggered by Cybersecurity Failures
Cybersecurity risk isn’t just about limiting data loss anymore, it’s increasingly about legal exposure at the highest corporate level. A recent massive data breach at Coupang, one of South Korea’s largest online retailers, may fundamentally change how publicly traded companies and their cybersecurity providers think about risk ...
Your Statement of Work Is Your Security Program Playbook, Not Paperwork
Most MSPs treat the Statement of Work like something you do after the sale. A formality. A box to check. That mindset is exactly why scope creeps, expectations get fuzzy, and security ends up feeling hard to prove when a ...
Cyber Lawsuits Are the New Cyber Threat: What Every MSP Needs to Know About Economic Loss and Legal Exposure
In 2024, class action lawsuits cost businesses over $42 billion globally. But for MSPs, the costliest threat isn’t ransomware—it’s litigation. And the legal doctrines you're relying on to protect you? They're not nearly as safe as you think. Class action ...
Stop Building Custom Security Programs. They Will Burn You.
Every MSP has lived this moment. A client calls and says they want a “custom” security program. They want their policies to sound like them. They want controls that are “unique to their workflow.” They want you to bend your ...
How MSPs Can Lead Clients Through CMMC Implementation
Introduction With the Department of War (née Department of Defense)’s Implementation of CMMC 2.0 now set to begin on November 10, 2025, MSPs have a strategic window to position themselves as trusted cybersecurity and compliance partners. Many of your existing ...
Why Treating AI Like Your IT Doctor Is Putting Your Business at Risk
Right now, millions of people are experimenting with AI tools as if they were personal doctors. They type in their symptoms, ask for a diagnosis, and walk away with treatment advice—all without ever seeing a medical professional. It feels fast, ...
The Annual Tradition of Forgetting Everything We Learned About Cybersecurity
Because nothing says “security first” like annual PowerPoint fatigue. Well, it’s that time of year again. Pumpkin-spiced coffee, ghosts and goblins, trees turning colors, and holiday ads airing entirely too early. Oh yeah, and Cybersecurity Awareness Month! I almost forgot. ...
The Cybersecurity Test You Think You're Passing (You're Not)
We were just running a security assessment for a 150-person company last week. Nice organization. Professional. Fancy logos on their trucks. Well-funded. And in about 11 minutes, we were inside their network. Here’s how it started: We sent an email. ...
Why Your Business Can’t Hide a Data Breach—And Who’s Watching
When your business suffers a data breach, the impact extends far beyond lost data and shaken trust. What many companies don’t realize is that plaintiff attorneys are actively monitoring breach reports—looking for opportunities to file lawsuits against breached organizations. Where ...
Do You Really Want the Cheapest Security Money Can Buy?
Let’s be honest—nobody brags about buying the cheapest parachute. Or hiring the cheapest brain surgeon. Or getting the cheapest babysitter off Craigslist. And yet, when it comes to cybersecurity, business leaders keep searching for the “most affordable” option—like it’s a ...
The “Free AI Tool” That Just Invited Hackers Into Your Business
Picture this: It’s Tuesday afternoon. Sharon from accounting is drowning in spreadsheets. She Googles: “Best free AI tool to make Excel easier.” She finds one. It promises magic. She clicks. She downloads. And just like that, hackers just scored VIP ...


