STATUS: SECURE – The Cyber Threat Briefing

WatchUr6 - Cybersecurity

You cannot be secure if you do not know the threat. On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy. Welcome to Status: Secure, the weekly cyber threat briefing for executives who refuse to operate in the blind. Hosted by the WatchUr6 collective, this show unites the battlefield with the boardroom. Featuring former Army Special Forces and Naval Special Warfare communications operators alongside an industry-leading CISO nominated for Cybersecurity Woman of the World. Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure. The enemy is listening. Is your status secure?

  1. 2d ago

    028 The Meta Child-Safety Ruling, Ethical AI, and Insider Threats: A Briefing for Both Sides

    This week's briefing comes down to one word: trust. Three stories that look separate and turn out to be the same story. We open with the largest child-safety ruling against a social media company to date — a New Mexico judge ordering Meta to pay an additional $567 million, bringing the total to $942 million, for allowing bad actors to operate on its platform. The judge called Meta a "public nuisance," comparing the platform to a polluting factory. Meta disagrees and is appealing. But the security lesson stands: platform security isn't only about the hackers outside your walls — it's about who you allow to operate inside them. From there, our CISO takes us one layer down into the ethics of AI and the integrity problem — why the "I" in the CIA triad is the security pillar quietly breaking in the AI era, and the four rules that keep an AI system honest so it can't lie to you even by accident. Then the big one: what the historic wave of layoffs means for insider threat. Why most insider incidents involve people already on their way out, why disabling an email address is nowhere near enough, and how a forgotten account can get your cyber-insurance claim denied. And finally, the other side of the briefing — a direct word to anyone who's been laid off about why retaliation turns a grievance into a criminal act, and how to redirect that energy instead. Intel Declassified in this Briefing: [00:32] The Meta child-safety ruling — $567M more, $942M total, and why it's a security story about who operates inside your walls.[03:36] Ethical AI and the integrity problem — the CIA triad and the four rules of trustworthy AI.[08:13] Three moves to keep your platform and AI on the right side of trust — plus the customer-service AI asked how to build a bomb.[12:02] Insider threat and the layoff wave — the three categories of insider risk and the $19.5M price tag.[16:52] The departure window — 245,953 tech layoffs in 2025 and why the 30 days around an exit are the most dangerous.[19:42] Why offboarding fails — the 83% who keep access, and the denied insurance claim.[22:34] A word to the laid off — don't turn a grievance into a criminal act. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/028-meta-child-safety-ruling-ethical-ai-insider-threats/Read the Associated Sitrep: How Trustworthy Is Your AI? A Data Integrity Standard for Your Organization: https://watchur6.com/sitrep/compliance-protocols/how-trustworthy-is-your-ai-data-integrity-standard/

  2. Aug 11

    027 The Minnesota Water Hack, AI Threats at Black Hat, and the Case for Age Limits on AI

    This week we went off script. Our CISO called in from the floor of Black Hat in Las Vegas — where she'd been invited to speak on AI and child privacy — for a wide-ranging briefing on the threats defining right now. We open with the Iranian-affiliated cyberattack that knocked a Minnesota water utility onto manual operations. The headline sounds sophisticated. The reality is the opposite: the attackers didn't break anything clever. They walked in through factory default passwords nobody changed, then locked out the real operators. The drinking water stayed safe, the blast radius was small — but the lesson is enormous, because it's the same one that applies to your organization. The most preventable vulnerability is the one you already know how to fix and haven't. Then we take you onto the Black Hat floor, where one topic swallowed everything else: securing AI. Five startups pitched a CISO panel and all five were about AI. We get into the shift from AI assistants to autonomous agents, the "how do you protect what you don't know you have" problem, and the CISO's three biggest current threats. And we close on her sharpest take of the year — that AI and social media, like driving and drinking, are dangerous enough to warrant age limits. The through-line from a water tower to a frontier AI model is the one this show returns to every week: the basics still win. Intel Declassified in this Briefing: [00:32] The Minnesota water attack — what happened, and why water is historically a hard target.[02:36] "They're testing us" — the magician's-misdirection problem with nation-state probing.[06:41] Impact and blast radius — why the security world didn't panic over this one.[08:36] Factory default passwords — the front door left open, and how the attackers walked in.[12:42] Live from Black Hat — why every startup in the room is racing to secure AI.[16:44] The three threats that matter most — ethics-free attackers, agents with no judgment, and a generation with no privacy.[21:41] The case for age limits on AI — the driving-and-drinking argument for gating dangerous technology. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/027-minnesota-water-hack-black-hat-ai-age-limits/Read the Associated Sitrep: The Agentic AI Security Gap — Governing Autonomous AI Before It Governs You: https://watchur6.com/sitrep/threat-intelligence/agentic-ai-security-gap-governance-guardrails/

  3. Aug 4

    026 World Leaks Extortion, Quishing Attacks, and Inside the Latest Health-ISAC Threat Briefing

    This week our CISO takes you somewhere most healthcare leaders never get to go — inside a nationwide Health-ISAC threat briefing, the healthcare sector's own member-only intelligence-sharing call, including a business continuity exercise run across more than 500 organizations. First, the two threats the sector is tracking right now. World Leaks, a data-theft extortion group that steals your data and leaks or sells it whether or not you pay, which means your backups won't save you. And quishing — QR-code phishing, alongside ClickFix and FileFix — social-engineering attacks that slip past your filters because a QR code is an image, not a scannable link, and the payload only resolves when someone scans it on a personal phone outside your controls. Then the part you can't get anywhere else: a firsthand readout of a sector-wide business continuity exercise, where a shared cloud identity provider goes down and takes much of healthcare with it. How long can you limp along on manual workarounds? Where are you in the incident-response queue when a hundred other organizations need the same responders? And why does patient safety set the recovery priority for the entire sector? The throughline: you were never meant to defend alone. Intel Declassified in this Briefing: [01:06] World Leaks and the extortion model that ignores your industry — and why backups don't save you from a leak.[03:51] Quishing, ClickFix, and FileFix: how QR-code attacks beat the URL filters that stop traditional phishing.[05:32] Three moves against both threats — treat QR codes like unknown links, assume the breach is a leak, and plug into your sector's ISAC.[06:59] What Health-ISAC actually is, why you can't just join, and the 1,200-plus alerts it sent the sector last year.[09:00] Why healthcare cyber is patient safety, not IT — the prescription that can't reach the pharmacy and the hospital with nowhere to divert.[11:16] The exercise: when a shared cloud identity provider goes down and takes the sector with it, and the incident-response queue nobody plans for.[16:22] Teach the teacher — vary who runs your continuity exercise, build a threat-intel program, know where you rank, and why it always comes back to people. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/026-world-leaks-quishing-health-isac-threat-briefing/Read the Associated Sitrep: When the Cloud Goes Down for Everyone — Business Continuity Planning for Healthcare's Shared-Vendor Risk: https://watchur6.com/sitrep/mission-resilience/healthcare-business-continuity-shared-cloud-vendor-risk/

  4. Jul 28

    025 Data Extortion, Credential Attacks, and the New HIPAA Security Rule Every Executive Must Know

    Ransomware evolved, and the evolution invalidates a defense most healthcare organizations still rely on. Attackers stopped just encrypting your data and started stealing it first. You can pay, restore from backup, and still watch your patient records get sold. The backup that used to be your leverage now solves half the problem. And they're not breaking in to do it. They're logging in — using credentials harvested at industrial scale and AI-written phishing that has none of the tells your staff was trained to catch. Healthcare is absorbing 2.3 ransomware attacks a day and has carried the most expensive breaches of any industry for fourteen straight years. The government's response is the first major HIPAA Security Rule overhaul since 2013 — and it kills the word that let organizations defer their most expensive controls for two decades: addressable. Intel Declassified in this Briefing: [00:33] The Ransomware Evolution: Why steal-and-extort broke the backup defense, and what it means when restoring your systems doesn't un-leak your patient data.[01:34] The Log In, Don't Break In Economy: 24 billion exposed credential records, AI-assisted phishing in 40 to 56 percent of sampled emails, and the Exchange flaw compounding both.[03:06] The Lock on the Door: Why credential attacks are just physical social engineering transplanted — attackers don't pick the lock, they take your keycard.[04:25] Back to the Basics: Phishing-resistant MFA on every account touching sensitive data, knowing where your data lives and minimizing it, and the gap between the patch cycle you claim and the one you run.[06:36] The New HIPAA Security Rule: The first overhaul since 2013, why Change Healthcare and 2.3 attacks a day forced it, and the elimination of required versus addressable.[09:16] What Becomes Mandatory: Encryption, MFA, segmentation, asset inventory and network map, scanning, pen testing, and 72-hour restoration — plus where our CISO thinks the rule's own floors are too low.[13:05] The Marching Orders: Run the risk analysis and map your data flows, reopen every addressable gap you deferred, and actually verify your business associates. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/025-data-extortion-credential-attacks-new-hipaa-security-rule/Read the Associated Sitrep: The HIPAA Security Rule Overhaul — A Readiness Roadmap for Healthcare Before the Clock Starts: https://watchur6.com/sitrep/compliance-protocols/hipaa-security-rule-overhaul-readiness-roadmap/

  5. Jul 21

    024 The CMMC Phase II Suspension: What Defense Contractors Need to Do Now

    Two days after we walked defense contractors through the CMMC certification timeline, the Department of War suspended Phase II. So we broke format for a rapid-response briefing. On July 13, 2026, the Department suspended the mandatory third-party C3PAO certification requirement that was set to take effect November 10 — effective immediately, across pending and future solicitations and contracts — and launched a 60-day review under a new CMMC Reform Task Force. Here is the part contractors are about to get wrong. The government paused a certification mechanism. It did not pause your obligation to protect federal data. Phase I self-assessments are still in place. NIST SP 800-171 and the 110 controls are still the standard. DFARS 252.204-7012 still binds you. And with third-party verification suspended, the accuracy of your own self-attestation is now your primary False Claims Act exposure, not a lesser one. "Suspended" is not "safe." It is breathing room. And the contractors who use it to get genuinely secure will be ready when the reformed program lands. Intel Declassified in this Briefing: [00:32] What the Department of War Announced: The immediate suspension of CMMC Phase II, the paused November 10 deadline, and the 60-day review under the new CMMC Reform Task Force.[02:20] The RFI Window: Why the Department CIO's Request for Information form is your chance to tell the government what the compliance burden actually looked like from a small business's side.[04:13] What Did NOT Change: Phase I self-assessments, the 110 NIST 800-171 controls, DFARS 252.204-7012, the government's right to audit, and False Claims Act exposure — all fully intact.[07:21] The C3PAO Bottleneck: How a limited assessor pool plus a hard deadline created a pricing squeeze on small businesses, and why Phase II is coming back regardless.[08:54] If You Were Mid-Certification: Why the right move is to breathe and spend deliberately rather than stop — and why you have time, but not forever.[11:05] The Marching Orders: Be honest about your self-assessment, close your gaps, submit the RFI, and watch the 60-day clock. Slow is smooth, smooth is fast. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/024-cmmc-phase-2-suspension-what-defense-contractors-do-now/Read the Associated Sitrep: CMMC Phase II Suspended — What the Department of War's Announcement Actually Means for Defense Contractors: https://watchur6.com/sitrep/compliance-protocols/cmmc-phase-2-suspended-what-it-means-defense-contractors/

  6. Jul 14

    023 Ransomware-as-a-Service, AI Phishing, and Everything You Need to Know About CMMC Level 3

    Cyberattacks are now a subscription business. Ransomware-as-a-service has erased the skill barrier so anyone can rent the malware and launch an attack, and AI-generated phishing has erased the warning signs a decade of training taught people to spot. In this episode we cover the threat economy hitting every sector, the three controls that actually blunt it, and then everything defense contractors need to know about CMMC — because the calendar just got real. Level 2 third-party certification is mandatory now. Level 3 arrives in 2027. And there is no Level 3 without Level 2 first. For the defense industrial base, the 2027 clock has already started. Intel Declassified in this Briefing: [00:32] Ransomware-as-a-Service: How cybercrime industrialized into a rentable subscription business, the DarkSide affiliate model, and why backups no longer save you when the data is stolen first.[04:09] AI Phishing Erased the Tells: Why generative AI writes perfect internal-looking emails, how deepfake voice clones an executive from about eight seconds of audio, and the IBM finding that 16% of breaches now involve AI.[07:24] The Three Universal Marching Orders: Phishing-resistant MFA and verification protocols, immutable and tested backups, and network segmentation to shrink the blast radius.[09:05] CMMC Level 2 Is Mandatory Now: Why self-attestation is over, what a C3PAO is, and why subcontractors and joint ventures each have to be certified independently.[14:13] Why Level 3 Makes Level 2 Urgent: The hard dependency — you cannot start a Level 3 assessment without Final Level 2 first — plus who actually needs Level 3 and what DIBCAC assessment involves.[21:03] The Affirmation on Your Signature: How a self-attestation you can't now certify becomes a False Claims Act exposure, and why the verified assessment protects the executive who signs. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/023-ransomware-as-a-service-ai-phishing-cmmc-level-3/Read the Associated Sitrep: The CMMC Level 2 Certification Timeline — Why the Road to Level 3 Starts Now for Defense Contractors: https://watchur6.com/sitrep/compliance-protocols/cmmc-level-2-certification-timeline-path-to-level-3/

  7. Jul 7

    022 OT Attacks, AI Risk, and Data Security in the Oil and Gas Industry

    The most important fact about the Colonial Pipeline attack is the one most people forget: the ransomware never touched the pipeline. It hit the billing and IT systems — and half the East Coast's fuel supply still shut down for six days, because the company couldn't prove the two worlds were separated. This is a special briefing. The CISO just got back from speaking on a panel at the Data Driven Oil & Gas USA 2026 conference in Houston, so we go deep on the energy sector — the OT attacks crossing from IT into the systems that physically run operations, the AI rush wiring operational data straight into the control room, and the data security discipline that decides whether an operator rides the wave or wipes out. And while the focus is oil and gas, the core lesson reaches every organization that connects physical operations to an IT network — which in 2026 is nearly everyone. Intel Declassified in this Briefing: [00:32] OT Attacks Cross the IT/OT Line: Why ransomware and wiper activity now hit industrial organizations hardest, and why OT was built for reliability, not security.[03:32] Unsophisticated Attackers Are Still Winning: The CISA, FBI, DOE, and EPA joint advisory on default credentials and exposed remote access — and the nation-state pre-positioning underneath it.[09:19] The Three Universal Marching Orders: Get internet-facing assets off the public internet, segment the network to shrink the blast radius, and detect the intruder who's already inside.[12:16] The AI Rush and IT/OT Convergence: Inside the Houston panel — the $200–400B opportunity, why only 15% of organizations are true AI leaders, and how connecting OT to AI opens a door that runs both ways.[19:28] Case Study, Colonial Pipeline: One legacy VPN account, no MFA, 100GB stolen in two hours, and a six-day shutdown of half the East Coast's fuel — without the attackers ever touching a control system.[24:31] Securing Your Data: Fix the identity gaps, govern operational data as a security asset, and pressure-test the shutdown decision through real functional exercises. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/022-ot-attacks-ai-risk-data-security-oil-gas/Read the Associated Sitrep: IT/OT Convergence Security — How Oil & Gas Operators Ride the AI Wave Without a Colonial Pipeline Repeat: https://watchur6.com/sitrep/mission-resilience/it-ot-convergence-security-oil-gas-ai/

  8. Jun 30

    021 AI Voice Fraud, Payment Breaches, and Everything You Need to Know About PCI DSS & NACHA

    For a decade we taught people to spot the phishing email by its bad grammar and awkward phrasing. AI has erased every one of those tells. The phishing email is now perfect, and the voice on the phone approving a wire transfer sounds exactly like your CFO. In this episode we cover the two threats hitting finance hardest in 2026 — AI-driven voice and deepfake fraud, and the e-skimming payment breaches stealing card data in the browser before it ever reaches a back-end system — then deliver the foundational briefing on the two standards that govern payment security: PCI DSS for cards, and NACHA's brand-new fraud monitoring rules for ACH. The lesson that ties it all together: Heartland Payment Systems was fully PCI DSS compliant when it suffered one of the largest card breaches in history. The standard is the floor, not the finish line. Intel Declassified in this Briefing: [00:32] AI Has Erased the Phishing Tells: Why generative AI and deepfake voice defeat a decade of "spot the typo" training, and the IBM finding that 16% of breaches now involve AI-driven attacks.[04:50] Why Your Technical Controls Don't Stop This: How AI fraud bypasses your MFA and firewall entirely by attacking the human authorization step instead of the technology.[05:40] Payment Breaches Have Moved to the Browser: E-skimming, Magecart, and formjacking — how card data is stolen as the customer types it, outside your back-end, with your logs showing nothing.[10:45] The Heartland Paradox: How a fully PCI DSS-compliant company suffered one of the largest card breaches in history, and why compliance is the baseline, not security.[11:30] What PCI DSS Actually Is: Why it's a contractual standard and not a government regulation, who's in scope, the 12 requirements, the four merchant levels, and the QSA / ROC / SAQ / ASV / AOC vocabulary.[16:51] PCI DSS v4.0.1 — The Grace Period Is Over: All 64 requirements now mandatory, the payment page as an explicit attack surface, expanded MFA, 12-character passwords, and the annual risk analysis.[20:47] How PCI Is Enforced and What a Breach Costs: The $5,000–$100,000 monthly fines, the $50–$90 per-record breach math, and why a breach can shut a smaller business down for good.[23:33] NACHA — The New ACH Fraud Rules Live This Week: How Phase 2 eliminated the volume threshold, the new "False Pretenses" category targeting credit-push fraud, and why the receiving bank now shares the monitoring duty. Mission Links: Verify your Security Posture: https://watchur6.com/secureWant to Hire us: https://watchur6.com/contact/View the Show Notes: https://watchur6.com/podcast/021-ai-voice-fraud-payment-breaches-pci-dss-nacha/Read the Associated Sitrep: The NACHA 2026 Fraud Monitoring Rules — A Finance Leader's Guide to ACH Credit-Push Compliance: https://watchur6.com/sitrep/compliance-protocols/nacha-2026-fraud-monitoring-rules-ach-compliance/

About

You cannot be secure if you do not know the threat. On the battlefield, the ability to communicate securely isn't a "nice to have"—it is the difference between life and death. In business, it is the difference between solvency and bankruptcy. Welcome to Status: Secure, the weekly cyber threat briefing for executives who refuse to operate in the blind. Hosted by the WatchUr6 collective, this show unites the battlefield with the boardroom. Featuring former Army Special Forces and Naval Special Warfare communications operators alongside an industry-leading CISO nominated for Cybersecurity Woman of the World. Each week, we decode the latest threats targeting Healthcare, Government Contracting, Finance, and Tech, and give you the tactical playbook to keep your lines open and your data secure. The enemy is listening. Is your status secure?