{"title":"Spoiledlunch","description":"Nerdy Stuff. Tech Talk. Zero Freshness.","subtitle":"Analysis and commentary on GRC, security, and AI.","articles":[{"title":"Risk Registers Become Graveyards for Unowned Problems","url":"/articles/2026-05-01-why-risk-registers-become-graveyards-for-unowned-problems/","date":"2026-07-28","summary":"Most risk registers start as decision tools and end as storage.\nThat is the failure.\nIn theory, the register is where an organization records meaningful risks, assigns ownership, …"},{"title":"Why Retrieval Quality Is Becoming a Governance Problem","url":"/articles/2026-05-01-why-retrieval-quality-is-becoming-a-governance-problem/","date":"2026-07-21","summary":"Retrieval quality is often discussed like a tuning problem.\nImprove chunking. Improve ranking. Improve metadata. Improve the prompts wrapped around the retrieved context. All of …"},{"title":"World Emoji Day: Pure Manufactured Awareness Theater","url":"/articles/2026-07-17-world-emoji-day-the-purest-form-of-manufactured-awareness-theater/","date":"2026-07-17","summary":"Today is World Emoji Day, which means it\u0026rsquo;s time to celebrate\u0026hellip; what exactly? Unicode standardization? Digital communication evolution? The commodification of human …"},{"title":"Internal PKI Problems Keep Becoming Outage Risks","url":"/articles/2026-05-01-why-internal-pki-problems-keep-quietly-becoming-outage-risks/","date":"2026-07-14","summary":"Internal PKI has a special talent for being treated as somebody else\u0026rsquo;s plumbing right up until it breaks something important.\nThen everyone remembers, very suddenly, that …"},{"title":"The Problem With Single Pane of Glass Security","url":"/articles/2026-07-08-the-problem-with-single-pane-of-glass-security-platforms/","date":"2026-07-08","summary":"Every generation of security platform marketing rediscovers the same pitch: too many tools, too much context switching, analysts drowning in disconnected consoles. The solution is …"},{"title":"Asset Inventory Is Still an Embarrassing Problem","url":"/articles/2026-05-01-why-asset-inventory-is-still-the-most-embarrassing-security-problem-in-large-organizations/","date":"2026-07-07","summary":"For an industry that loves the word visibility, security remains remarkably bad at answering the oldest infrastructure question in the room: what do we actually have?\nThat should …"},{"title":"Global Information Security Day: A Vendor-Made Holiday","url":"/articles/2026-06-30-global-information-security-day-how-the-security-industry-invented-a-holiday-for-itself/","date":"2026-06-30","summary":"Today is Global Information Security Day, an awareness holiday you\u0026rsquo;ve probably never heard of despite eleven years of \u0026ldquo;global\u0026rdquo; celebration. That\u0026rsquo;s because …"},{"title":"AI Usage Discovery Is the New Shadow IT Problem","url":"/articles/2026-05-01-why-ai-usage-discovery-is-becoming-the-new-shadow-it-problem/","date":"2026-06-30","summary":"For years, shadow IT meant unsanctioned SaaS, unmanaged devices, and business teams adopting systems faster than central governance could track them.\nNow the same pattern is …"},{"title":"AI Incident Response Is Underbuilt Almost Everywhere","url":"/articles/2026-05-01-why-ai-incident-response-is-still-underbuilt-almost-everywhere/","date":"2026-06-23","summary":"Most organizations now have some language about responsible AI.\nFar fewer have a credible answer to a simpler question: what happens when an AI system causes a production problem …"},{"title":"The SIEM Did Not Fail; Your Data Model Did","url":"/articles/2026-05-01-the-siem-did-not-fail-your-data-model-did/","date":"2026-06-16","summary":"Security teams love to declare that the SIEM failed them. It is a clean story. The platform was noisy, expensive, slow, or hard to operate. Leadership understands vendor …"}],"news":[{"title":"SEC Announces Continuation of Small Business Advisory Committee Meeting","url":"/news/2026-07-30-sec-announces-continuation-of-small-business-advisory-committee-meeting/","date":"2026-07-30","summary":"Summary: The Securities and Exchange Commission announced that the Small Business Capital Formation Advisory Committee meeting held on July 21, 2026, will …"},{"title":"MikroTik RouterOS","url":"/news/2026-07-30-mikrotik-routeros/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router\u0026rsquo;s WireGuard private key in …"},{"title":"Mitsubishi Electric CC-Link IE TSN Communication Protocol","url":"/news/2026-07-30-mitsubishi-electric-cc-link-ie-tsn-communication-protocol/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with …"},{"title":"NASA Core Flight System (cFS) Health ＆ Safety (HS) Application","url":"/news/2026-07-30-nasa-core-flight-system-cfs-health-safety-hs-application/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.\nWhy it matters: This …"},{"title":"Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module","url":"/news/2026-07-30-rockwell-automation-compactlogix-5380-controllogix-5580-1756-en4tr-communications-module/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.\nWhy it matters: This …"},{"title":"Schneider Electric IGSS","url":"/news/2026-07-30-schneider-electric-igss/","date":"2026-07-30","summary":"Summary: View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) …"},{"title":"Toptech Systems RCU II+ and Multiload II+","url":"/news/2026-07-30-toptech-systems-rcu-ii-and-multiload-ii/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or …"},{"title":"Watchfire Controller Software","url":"/news/2026-07-30-watchfire-controller-software/","date":"2026-07-30","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update …"},{"title":"How enabling two settings tripled our scores on the ARC-AGI-3 benchmark","url":"/news/2026-07-29-how-enabling-two-settings-tripled-our-scores-on-the-arc-agi-3-benchmark/","date":"2026-07-29","summary":"Summary: How two API settings improved GPT-5.6 performance on ARC-AGI-3, boosting scores and efficiency by retaining reasoning and enabling compaction.\nWhy it …"},{"title":"2026 Minimum Elements for a Software Bill of Materials (SBOM)","url":"/news/2026-07-29-2026-minimum-elements-for-a-software-bill-of-materials-sbom/","date":"2026-07-29","summary":"Summary: CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for …"}]}