Logo
Search
Login
Sign Up
Oliver Buchannon
Ryan Bilak

Founder DoGood Founder LaptopReturn.com

Week Ahead: Patch Tuesday came late.

May 4, 2026

•

2 min read

Week Ahead: Patch Tuesday came late.

Four CVEs hit KEV last week. All four were exploited before disclosure. cPanel had a two-month silent zero-day window.

Ryan Bilak
Ryan Bilak
13 years hidden. 10 hours to exploit.

May 1, 2026

•

3 min read

13 years hidden. 10 hours to exploit.

A 13-year-old Apache ActiveMQ RCE found with AI. A Marimo flaw weaponized within 10 hours. The CVE clock just broke.

Ryan Bilak
Ryan Bilak
Buyers cut. Vendors merge. Same week.

Apr 29, 2026

•

2 min read

Buyers cut. Vendors merge. Same week.

Four network members rationalized four different categories in one week. Then ServiceNow closed Armis.

Ryan Bilak
Ryan Bilak
Week Ahead: SSO is the new perimeter

Apr 27, 2026

•

2 min read

Week Ahead: SSO is the new perimeter

ShinyHunters' ADT deadline hits today. Bitwarden CLI poisoned on npm. SimpleHelp flagged by CISA.

Ryan Bilak
Ryan Bilak
NIST Just Quit Scoring Most CVEs

Apr 24, 2026

•

3 min read

NIST Just Quit Scoring Most CVEs

NIST just stopped enriching most CVEs. KEV is the new priority signal. Plus: two Defender zero-days unpatched.

Ryan Bilak
Ryan Bilak
Observability priorities tripled in 60 days

Apr 22, 2026

•

2 min read

Observability priorities tripled in 60 days

Cloud observability is the #1 new buying category across the network. Q2 rate is 3.7x Q1.

Ryan Bilak
Ryan Bilak
Two Wormable RCEs in 163 Patches

Apr 17, 2026

•

3 min read

Two Wormable RCEs in 163 Patches

Microsoft buried two zero-click RCEs in its second-largest Patch Tuesday ever. Plus: Cisco ISE hits 9.9.

Ryan Bilak
Ryan Bilak
AI governance evals nearly 2x since Q1

Apr 15, 2026

•

3 min read

AI governance evals nearly 2x since Q1

1 in 4 IT leader priorities mention AI. The shift: from adoption to governance and control.

Ryan Bilak
Ryan Bilak
FBI Just Kicked Russia Off Your Router

Apr 10, 2026

•

6 min read

FBI Just Kicked Russia Off Your Router

APT28 hijacked 18,000 routers across 120 countries to spoof Outlook logins. Plus: a FortiClient EMS zero-day.

Ryan Bilak
Ryan Bilak
1 in 5 priorities now name a vendor to replace

Apr 8, 2026

•

3 min read

1 in 5 priorities now name a vendor to replace

Incumbent dissatisfaction has doubled since December. Across the network, renewals are no longer renewals.

Ryan Bilak
Ryan Bilak
Week Ahead: 766 Hosts in 24 Hours

Apr 6, 2026

•

3 min read

Week Ahead: 766 Hosts in 24 Hours

React2Shell harvests cloud secrets at scale. Cisco IMC opens admin access. CISA's AI deadline lands Wednesday.

Ryan Bilak
Ryan Bilak
100M Downloads. One Backdoor.

Apr 3, 2026

•

5 min read

100M Downloads. One Backdoor.

North Korea backdoored the most popular JavaScript HTTP library. Plus: Oracle, Citrix, and Chrome zero-days.

Ryan Bilak
Ryan Bilak
Data protection is now the #2 buying signal

Apr 1, 2026

•

3 min read

Data protection is now the #2 buying signal

DLP, DSPM, and data classification are surging across the network. Two months ago, identity held this spot.

Ryan Bilak
Ryan Bilak
Week Ahead: That "DoS" Is Now a 9.8 RCE

Mar 30, 2026

•

3 min read

Week Ahead: That "DoS" Is Now a 9.8 RCE

F5 reclassified a 5-month-old flaw as full RCE. Plus: supply chain attacks widen, and AI agents need identity governance.

Ryan Bilak
Ryan Bilak
Your firewall was a backdoor for 36 days.

Mar 27, 2026

•

4 min read

Your firewall was a backdoor for 36 days.

Interlock ransomware owned Cisco FMC for over a month before anyone noticed. Plus: a California city goes dark, and Teams becomes a vishing weapon.

Ryan Bilak
Ryan Bilak
Shadow AI is now the #1 buying signal across the network

Mar 25, 2026

•

3 min read

Shadow AI is now the #1 buying signal across the network

1 in 5 member priorities this month reference AI — and the gap everyone's trying to close is visibility.

Ryan Bilak
Ryan Bilak
Week Ahead: When Your Security Scanner Becomes the Threat

Mar 23, 2026

•

4 min read

Week Ahead: When Your Security Scanner Becomes the Threat

Stryker's 80K-device wipe, a backdoored vulnerability scanner, and 400 Salesforce orgs breached. Your week ahead.

Ryan Bilak
Ryan Bilak
Your firewall was owned for 5 weeks before anyone told you

Mar 20, 2026

•

3 min read

Your firewall was owned for 5 weeks before anyone told you

The real story isn't the CVE. It's what the disclosure timeline tells you about your detection assumptions.

Ryan Bilak
Ryan Bilak
The wiper came through Intune

Mar 13, 2026

•

7 min read

The wiper came through Intune

Plus: FortiGate configs are handing attackers your AD keys. Office Preview Pane executes code without a click.

Ryan Bilak
Ryan Bilak
Three years. No one noticed.

Mar 6, 2026

•

6 min read

Three years. No one noticed.

Plus: 40% of breaches required no authentication. Your Google Calendar is a C2 channel.

Ryan Bilak
Ryan Bilak
Your firewall had the default password

Feb 27, 2026

•

7 min read

Your firewall had the default password

Plus: BeyondTrust's second critical RCE in a year. CISA at 38% capacity.

Ryan Bilak
Ryan Bilak
Your backup tool has a hardcoded password

Feb 20, 2026

•

7 min read

Your backup tool has a hardcoded password

Plus: Copilot turns attack vector. Chrome's first zero-day of 2026.

Ryan Bilak
Ryan Bilak
Sleeper Webshells in Your MDM

Feb 13, 2026

•

7 min read

Sleeper Webshells in Your MDM

Plus: First malicious Outlook add-in. Apple's first zero-day of 2026.

Ryan Bilak
Ryan Bilak
Your firewall vendor just became an identity risk

Jan 30, 2026

•

7 min read

Your firewall vendor just became an identity risk

Fortinet disabled cloud SSO, an Office zero-day bypassed warnings, and 72M consumer records hit the dark web.

Ryan Bilak
Ryan Bilak
Active Exploitation: Cisco Unified Communications

Jan 23, 2026

•

7 min read

Active Exploitation: Cisco Unified Communications

Plus: AI assistants leaking data and why hiring just became an identity risk.

Ryan Bilak
Ryan Bilak
Load more

THE CXO BRIEF

© 2026 The CXO Brief.
Report abusePrivacy policyTerms of use
beehiivPowered by beehiiv