Teardown: Dark Clark, the Fake Think Tank That Filed Status Reports
On October 8, 2026, OpenAI banned two clusters of ChatGPT accounts running influence operations: one of Russian origin, one of Iranian origin. The…
Read →Teardowns, notes, and things I've taken apart.
On October 8, 2026, OpenAI banned two clusters of ChatGPT accounts running influence operations: one of Russian origin, one of Iranian origin. The…
Read →The most interesting detail in OpenAI's new report isn't that state actors used ChatGPT to write propaganda. It's that Russian operatives used it to…
Read →Anthropic just launched its Cyber Mission, and the most important line isn't the partner list.
Read →Two “companies” pitched a target on a bank-backed investment. Their domains, timing, and missing disclosures tell a different story.
Read →Analysts at managed security service providers say 53% of the alerts they get are false positives, and 44% say they ignore alerts when the queue gets…
Read →21 seconds. That's the median time between someone opening a phishing email and clicking the link, in the simulation data behind Verizon's 2024 DBIR…
Read →Spoofed mail got past controls that were supposed to stop it. The question was simple: why didn't anything block this?
Read →I didn't start in threat investigation. I started in Tier 1 support. Tier 1 to Tier 2. Then promoted into MSP Escalations based on investigation…
Read →Security awareness training teaches people to spot the sketchy link. The most expensive email attack usually doesn't have one.
Read →SOC teams get an average of 2,992 alerts a day, and 63% of them go unaddressed. (Vectra AI, 2026 State of Threat Detection and Response)
Read →The UI tells you what the product decided. The backend tells you why. When a case gets weird, I stop trusting the dashboard and start querying:
Read →I've documented and escalated 498 product defects to R&D. 315 of them reached DONE. Every one went in with logs, artifacts, and reproduction steps.
Read →In Vectra's 2023 survey of 2,000 security analysts, analysts estimated that 83% of the alerts they get are false positives.
Read →Microsoft's own guidance on compromised mailboxes lists suspicious inbox rules as a warning sign: rules that auto-forward mail to unknown addresses…
Read →Microsoft's 2025 Digital Defense Report: more than 97% of identity attacks are password spray or brute force, and identity-based attacks rose 32% in…
Read →Not every account takeover needs a password. Microsoft describes an illicit consent grant attack like this: the attacker registers an app in…
Read →Verizon's 2026 DBIR: 48% of breaches involved a third party, up from 30% the year before. In email, one of the nastiest versions of that is vendor…
Read →Microsoft Threat Intelligence tracked QR code phishing attacks rising from 7.6 million in January 2026 to 18.7 million in March. A 146% increase in…
Read →Since February 2024, Gmail has required anyone sending more than 5,000 messages a day to personal Gmail accounts to authenticate with SPF, DKIM and…
Read →Message trace is one of the most useful tools in email investigation. It's also one of the most over-trusted.
Read →21 seconds: the median time to click a phishing link after opening the email, in the simulation data behind Verizon's 2024 DBIR.
Read →In a 2024 study by Heiding, Schneier, Vishwanath and colleagues, fully AI-automated spear phishing emails got a 54% click-through rate. Phishing…
Read →IBM's 2026 Cost of a Data Breach report: organizations making extensive use of security AI and automation lowered their average breach costs by $1.93…
Read →Outside my day job, I test AI models the way I'd investigate anything else: assume nothing, collect evidence, look for patterns.
Read →From Verizon's 2024 DBIR: in phishing simulation data, 20% of users reported the phishing email, and 11% of the users who clicked it also reported it.
Read →In 2025, the FBI's Recovery Asset Team froze $679 million in fraudulent transfers, about 58% of the roughly $1.16 billion it went after. (FBI IC3…
Read →"The user clicked a phishing link" is a symptom, not a root cause. Walk a typical account compromise backward and the real questions show up:
Read →The most underrated investigation skill: explaining what you found to people who need different things from it.
Read →Change Healthcare told HHS's Office for Civil Rights that about 192.7 million people were affected by its breach.
Read →Verizon's 2026 DBIR found ransomware in 48% of breaches. Exploited vulnerabilities are now the top way in, per the same report. But email is still a…
Read →In ISC2's 2024 Workforce Study, women made up 22% of security teams on average. I'm one of them, and I didn't get here alone.
Read →What threat investigation actually takes, from three years in email security:
Read →Losses reported to the FBI passed $20 billion in 2025 for the first time, from more than 1 million complaints. (FBI IC3 2025 Internet Crime Report)
Read →