This website uses cookies

Read our Privacy policy and Terms of use for more information.

Download your field guide:
Gatorbyte #004 - readers can Save-as-PDF)

The Pulse

Progress ordered ShareFile customers to pull their Storage Zone Controllers offline — and still hasn't said why. On July 10, Progress told customers running ShareFile's self-hosted Storage Zone Controller to shut the servers down over what it called a "credible external security threat," with no detail yet on what the threat is or whether any controller was actually breached. Only the self-hosted controller is affected, not standard cloud ShareFile. If a client runs one: keep it offline until Progress clears it, confirm you're on 5.12.4+ or 6.x before restarting, and if it's internet-facing, treat it as a possible incident — preserve logs and check for unfamiliar .aspx files before assuming it's clean.

Your AI coding assistant might approve an edit it never actually showed you. Wiz disclosed GhostApproval this week — a symlink trick that works against six major AI coding tools (Amazon Q, Claude Code, Cursor, Windsurf, and others): a malicious repo points a harmless-looking filename at a sensitive one (like your SSH keys), and the approval dialog shows the harmless name while the agent writes to the real target. AWS, Cursor, and Google shipped fixes; two vendors haven't, and Anthropic disputes it's a bug at all. Either way: don't let coding agents run unattended against repos you didn't write, and don't treat an "approved" dialog as proof of what actually got touched.

The Hardened Stack
One fix, shippable before lunch: the Shadow AI discovery drill — 30 minutes, no new tools.

  1. The expense question (10 min).

    • Pull 90 days of card/expense data. Search: OpenAI, Anthropic, Claude, ChatGPT, Midjourney, Perplexity, Gemini, Copilot, Jasper, Otter, Fireflies, ElevenLabs.

    • Personal-card reimbursements count DOUBLE — that's someone who wanted the tool badly enough to float the cost themselves.

  2. The network question (10 min).

  3. The human question (10 min).

    • Ask team leads, verbatim: "What AI tools does your team use to get work done? Nobody's in trouble — I need the list to protect it."

    • Amnesty framing is the whole trick. Punish honesty once, go blind forever.

Then triage into three buckets: Approve (low-risk, real value — write it down) · Approve with rules (fine UNLESS client data, credentials, or regulated data goes in) · Replace (high-risk tool doing a job a sanctioned tool can do). That triage IS your first AI policy — the 1-page template in the kit turns it into a document you can hand a client.

The Boardroom Bridge

"I ran a quiet inventory. We have more AI in the building than we thought — that's normal, it's 2026. Most of it is harmless and some of it is genuinely making people faster. My concern is narrow: which tools are seeing customer data or credentials. So I'm proposing three things: a short approved list so people know what's safe, one rule — client data only goes into approved tools — and a quarterly re-check, because this list changes fast. Cost is near zero. The alternative is finding out what tools we used from a breach notification."

Why it works: normalizes instead of shames (people hide what gets punished), narrows scope to data classes (boards can reason about that), three concrete asks, ends on cost.

Quick Poll
0–2 (we're clean) 3–5 (about what I'd expect) 6–10 (uncomfortable) 10+ (please don't tell me) Haven't run it yet Cast Vote →

This week's tool + AxiomLens

The reason Dirty Frag triage and the Canvas vendor-risk question feel like two different fires is that, in most shops, they live in two different spreadsheets — and neither one computes anything. AxiomLens is the fix: a relational SQLite model over all 106 NIST CSF 2.0 subcategories that tells you your actual coverage as a number and writes the board report on demand — a deterministic template, not an AI guessing at your posture, no API key required. Locally owned: one-time license, per named user, node-locked to your machine, nothing phoning home after a one-time activation. The EULA carries a vendor-dissolution clause — if we ever close shop, you keep operating. Grab it during the founding window and one framework pack of your choice comes with it, free (ISO 27001, PCI DSS, and seven others to pick from). The kind of tool you can put in front of a vCISO, an MSP partner, or a procurement review without flinching.

Founding pricing: $599, then $999 at standard, stepping to $1,199 once the next major GUI update ships. It supports compliance documentation and audit-prep workflows; it's a tool, not a certification, and not a substitute for legal, compliance, or audit advice.

Get AxiomLens TSG’s Gumroad

Framework Packs (ISO 27001, PCI DSS, +7 more — $199 each) → TSG’s Gumroad

Want to see it run first?

Watch the walkthrough https://youtu.be/namYnNbox4k

Reply

Avatar

or to participate

Keep Reading