Alisha Gray

Policy, regulation & disclosure

Alisha covers the regulatory edge of cybersecurity — SEC disclosures, CIRCIA, NIS2, executive orders, sanctions on cyber actors. Trained as a lawyer.

Recent stories

Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign
Threat Intelligence
Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign
The add-ons concealed payloads in image and font files and activated days after install. Microsoft attributes the activity to a single actor operating since 2021.
Jun 29
Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP
Vulnerabilities
Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP
A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.
Jun 26
Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant
Threat Intelligence
Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant
Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.
Jun 26
Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Policy & Regulation
Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.
Jun 26
AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments
AI Security
AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments
A new framework aims to help security teams prioritize which supply chain vulnerabilities carry the highest operational, safety, and business risk where AI systems are in play.
Jun 24
Meta Halts AI Training Program Amid Data Access Breaches
AI Security
Meta Halts AI Training Program Amid Data Access Breaches
Meta's AI data collection halted after security breaches. Employees accessed restricted data, revealing gaps in the program.
Jun 24
Executive Order 14409 Locks In Federal PQC Deadlines: 2030 for Key Establishment, 2031 for Signatures
Policy & Regulation
Executive Order 14409 Locks In Federal PQC Deadlines: 2030 for Key Establishment, 2031 for Signatures
The June 22 order sets binding migration dates for high-value assets and high-impact systems, while leaving national security systems on a parallel track.
Jun 23
WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
Threat Intelligence
WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least ten jurisdictions.
Jun 23
DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
AI Security
DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.
Jun 22
Klue Breach Compromises Salesforce Data via OAuth Token Theft
Breaches
Klue Breach Compromises Salesforce Data via OAuth Token Theft
Unauthorized access exposes CRM data; threat actors exploit legacy credentials.
Jun 22
When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Policy & Regulation
When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.
Jun 22
Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
Breaches
Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.
Jun 19
Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Policy & Regulation
Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.
Jun 19
Security Protocols for SMBs Adopting Claude
AI Security
Security Protocols for SMBs Adopting Claude
Understanding and managing security risks with Claude’s AI solutions for small and medium-sized businesses.
Jun 19
Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Policy & Regulation
Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.
Jun 18
© 2026 Threat Vectr