Alisha Gray
Policy, regulation & disclosure
Alisha covers the regulatory edge of cybersecurity — SEC disclosures, CIRCIA, NIS2, executive orders, sanctions on cyber actors. Trained as a lawyer.
Recent stories

Threat Intelligence
Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign
The add-ons concealed payloads in image and font files and activated days after install. Microsoft attributes the activity to a single actor operating since 2021.
Jun 29

Vulnerabilities
Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP
A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.
Jun 26

Threat Intelligence
Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant
Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.
Jun 26

Policy & Regulation
Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.
Jun 26

AI Security
AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments
A new framework aims to help security teams prioritize which supply chain vulnerabilities carry the highest operational, safety, and business risk where AI systems are in play.
Jun 24

AI Security
Meta Halts AI Training Program Amid Data Access Breaches
Meta's AI data collection halted after security breaches. Employees accessed restricted data, revealing gaps in the program.
Jun 24

Policy & Regulation
Executive Order 14409 Locks In Federal PQC Deadlines: 2030 for Key Establishment, 2031 for Signatures
The June 22 order sets binding migration dates for high-value assets and high-impact systems, while leaving national security systems on a parallel track.
Jun 23

Threat Intelligence
WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least ten jurisdictions.
Jun 23

AI Security
DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.
Jun 22

Breaches
Klue Breach Compromises Salesforce Data via OAuth Token Theft
Unauthorized access exposes CRM data; threat actors exploit legacy credentials.
Jun 22

Policy & Regulation
When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.
Jun 22

Breaches
Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.
Jun 19

Policy & Regulation
Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.
Jun 19

AI Security
Security Protocols for SMBs Adopting Claude
Understanding and managing security risks with Claude’s AI solutions for small and medium-sized businesses.
Jun 19

Policy & Regulation
Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.
Jun 18