{"title":"Spoiledlunch","description":"Nerdy Stuff. Tech Talk. Zero Freshness.","subtitle":"Analysis and commentary on GRC, security, and AI.","articles":[{"title":"Why Retrieval Quality Is Becoming a Governance Problem","url":"/articles/2026-05-01-why-retrieval-quality-is-becoming-a-governance-problem/","date":"2026-07-21","summary":"Retrieval quality is often discussed like a tuning problem.\nImprove chunking. Improve ranking. Improve metadata. Improve the prompts wrapped around the retrieved context. All of …"},{"title":"World Emoji Day: Pure Manufactured Awareness Theater","url":"/articles/2026-07-17-world-emoji-day-the-purest-form-of-manufactured-awareness-theater/","date":"2026-07-17","summary":"Today is World Emoji Day, which means it\u0026rsquo;s time to celebrate\u0026hellip; what exactly? Unicode standardization? Digital communication evolution? The commodification of human …"},{"title":"Internal PKI Problems Keep Becoming Outage Risks","url":"/articles/2026-05-01-why-internal-pki-problems-keep-quietly-becoming-outage-risks/","date":"2026-07-14","summary":"Internal PKI has a special talent for being treated as somebody else\u0026rsquo;s plumbing right up until it breaks something important.\nThen everyone remembers, very suddenly, that …"},{"title":"The Problem With Single Pane of Glass Security","url":"/articles/2026-07-08-the-problem-with-single-pane-of-glass-security-platforms/","date":"2026-07-08","summary":"Every generation of security platform marketing rediscovers the same pitch: too many tools, too much context switching, analysts drowning in disconnected consoles. The solution is …"},{"title":"Asset Inventory Is Still an Embarrassing Problem","url":"/articles/2026-05-01-why-asset-inventory-is-still-the-most-embarrassing-security-problem-in-large-organizations/","date":"2026-07-07","summary":"For an industry that loves the word visibility, security remains remarkably bad at answering the oldest infrastructure question in the room: what do we actually have?\nThat should …"},{"title":"Global Information Security Day: A Vendor-Made Holiday","url":"/articles/2026-06-30-global-information-security-day-how-the-security-industry-invented-a-holiday-for-itself/","date":"2026-06-30","summary":"Today is Global Information Security Day, an awareness holiday you\u0026rsquo;ve probably never heard of despite eleven years of \u0026ldquo;global\u0026rdquo; celebration. That\u0026rsquo;s because …"},{"title":"AI Usage Discovery Is the New Shadow IT Problem","url":"/articles/2026-05-01-why-ai-usage-discovery-is-becoming-the-new-shadow-it-problem/","date":"2026-06-30","summary":"For years, shadow IT meant unsanctioned SaaS, unmanaged devices, and business teams adopting systems faster than central governance could track them.\nNow the same pattern is …"},{"title":"AI Incident Response Is Underbuilt Almost Everywhere","url":"/articles/2026-05-01-why-ai-incident-response-is-still-underbuilt-almost-everywhere/","date":"2026-06-23","summary":"Most organizations now have some language about responsible AI.\nFar fewer have a credible answer to a simpler question: what happens when an AI system causes a production problem …"},{"title":"The SIEM Did Not Fail; Your Data Model Did","url":"/articles/2026-05-01-the-siem-did-not-fail-your-data-model-did/","date":"2026-06-16","summary":"Security teams love to declare that the SIEM failed them. It is a clean story. The platform was noisy, expensive, slow, or hard to operate. Leadership understands vendor …"},{"title":"The KEV Catalog Is Useful, Not Prioritization Strategy","url":"/articles/2026-05-01-the-kev-catalog-is-useful-but-it-is-not-a-prioritization-strategy/","date":"2026-06-09","summary":"The Known Exploited Vulnerabilities catalog is one of the better things to happen to enterprise vulnerability management in years. It gives defenders a cleaner signal than generic …"}],"news":[{"title":"Small Business Forum's Report to Congress Highlights Recommendations to Improve Capital-Raising Policy","url":"/news/2026-07-27-small-business-forum-s-report-to-congress-highlights-recommendations-to-improve-capital-raising-policy/","date":"2026-07-27","summary":"Summary: The Securities and Exchange Commission released a report to Congress today highlighting policy recommendations from the SEC’s 45th Annual …"},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","url":"/news/2026-07-27-cisa-adds-two-known-exploited-vulnerabilities-to-catalog/","date":"2026-07-27","summary":"Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.\nWhy it matters: …"},{"title":"FTC Takes Action Against Elite Events for Bypassing Ticket Purchase Limits in Violation of Better Online ...","url":"/news/2026-07-27-ftc-takes-action-against-elite-events-for-bypassing-ticket-purchase-limits-in-violation-of-better-online/","date":"2026-07-27","summary":"Summary: Ticket broker Elite Events and its operators will pay $300,000 in civil penalties to resolve Federal Trade Commission allegations that the firm …"},{"title":"How AI is expanding what people do at work","url":"/news/2026-07-27-how-ai-is-expanding-what-people-do-at-work/","date":"2026-07-27","summary":"Summary: New OpenAI research shows how AI is expanding what workers do, with ChatGPT users taking on tasks across roles and reshaping job boundaries.\nWhy it …"},{"title":"SEC Announces Roundtable on Preparations for 24-Hour Trading","url":"/news/2026-07-23-sec-announces-roundtable-on-preparations-for-24-hour-trading/","date":"2026-07-23","summary":"Summary: The Securities and Exchange Commission announced today that it will host a roundtable on Sept.\nWhy it matters: This matters if it changes how teams …"},{"title":"CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported ...","url":"/news/2026-07-23-cisa-nsa-fbi-and-partners-warn-zimbra-collaboration-suite-users-of-ongoing-russian-state-supported/","date":"2026-07-23","summary":"Summary: CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported \u0026hellip;\nWhy it matters: This matters if it …"},{"title":"Johnson Controls C-CURE 9000 and Victor application server","url":"/news/2026-07-23-johnson-controls-c-cure-9000-and-victor-application-server/","date":"2026-07-23","summary":"Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.\nWhy it …"},{"title":"Johnson Controls XAAP Android","url":"/news/2026-07-23-johnson-controls-xaap-android/","date":"2026-07-23","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.\nWhy it …"},{"title":"MZ Automation lib60870","url":"/news/2026-07-23-mz-automation-lib60870/","date":"2026-07-23","summary":"Summary: View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.\nWhy it …"},{"title":"MZ Automation libIEC61850","url":"/news/2026-07-23-mz-automation-libiec61850/","date":"2026-07-23","summary":"Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 …"}]}