Bizarus.
Home › Topics › Cybersecurity

Cybersecurity

Vulnerability research, disclosure practice and the economics of exploitation.

Research
Evidence Review19 Aug 2026
A field trial sent 19,500 hospital staff ten phishing lures over eight months. Training changed almost nothing.
Nearly every organisation trains staff against phishing. An eight-month randomised trial of more than 19,500 hospital employees, published at IEEE Security and Privacy, found annual awareness training had no significant effect on who fell for a simulated lure, and the post-click "you clicked" training reduced click likelihood by about two percentage points. What the email pretended to be mattered far more than whether the reader had been trained. We read the study, its limits, and a converging field experiment, and ask what the evidence actually supports.
Evidence Review8 Aug 2026
1.3 billion leaked passwords, mapped by country: what a global password security index actually shows
An analysis of 1.3 billion breached credentials across 69 countries and institutions found that complexity rules alone don't fix weak passwords, and that government domains score high on structure but stay predictable.
Blog
Argument16 Aug 2026
Cheap to find, expensive to check: what curl, NIST and DARPA each did about it
In eight months, curl closed a bug bounty that had confirmed 87 real vulnerabilities, NIST stopped enriching most CVEs in the National Vulnerability Database, and DARPA's AI Cyber Challenge showed autonomous systems finding and patching vulnerabilities at 152 dollars a task. These are usually read as three unrelated stories. They share a mechanism: the cost of producing something that looks like a security finding has collapsed, and the cost of establishing whether it is true has not moved. The variable that separates the institution that thrived from the ones that narrowed is what each asked people to prove.
News
Development21 Aug 2026
Five US agencies warn attackers are using AI to write exploit tools for Siemens industrial controllers
On August 19 the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency issued a joint advisory warning that attackers are pairing AI-assisted scripting with open-source automation libraries to build tools that read from and write to internet-exposed Siemens S7 programmable logic controllers used in water, energy, chemical and manufacturing facilities. The agencies call it an active threat, assess the current activity as reconnaissance ahead of possible disruption, and stop short of attributing it to any group.
Development12 Aug 2026
Ransom Cartel ransomware creator sentenced to 16 years in US federal prison
Belarusian national Maksim Silnikau was sentenced to 16 years for running the Ransom Cartel ransomware-as-a-service operation.
← All topics
© 2026 Bizarus AI