Please turn JavaScript on
header-image

The Nine Lives Brief

Subscribe to Nine Lives, Zero Trust, and get security insights delivered to your inbox.

Here's what you'll get:

  • Zero Trust insights you can actually use

  • DevSecOps practices for building security into your pipeline

  • Threat intel worth knowing

  • Cloud security tips from the trenches

  • Secure coding and shift-left strategies

  • The occasional cat pun (we're paranoid about spam, not fun)

Whether you're building secure infrastructure, automating compliance, or navigating the multi-cloud maze, this newsletter has you covered.

Filter by topic to get precisely what you need. Unsubscribe anytime.

Stay curious. Stay secure. Land on your feet.

Message History

Nearly 70% of incidents in the Americas now begin with stolen or misused accounts. Infostealers are the engine behind that number – families like Lumma, RedLine, and Vidar export browser cookies and session tokens directly from the victim’s machine, bypassing MFA entirely because the stolen token already carries the authentication claim. IBM X-Force tracked more than 16 milli...


Read full story

After a compromised service principal incident, the first triage question is always the same: “What else can this identity reach?” The answer usually lives outside Sentinel, buried in entitlement exports, RBAC snapshots, or asset inventories that nobody wanted to pay analytics-tier ingestion costs to store.

On April 1, 2026, Microsoft shipped two Sentinel feat...


Read full story

Last January, I published a post on building an LLM Firewall with AWS Lambda — an app-level proxy that inspects prompts between a user and the model. It worked, but it required custom code, per-app deployment, and had no visibility into AI traffic you didn’t control.

The fund...


Read full story

New in 2026: Microsoft shipped two major AI security capabilities in early 2026: Defender for AI for real-time threat protection and the Security Dashboard for AI for unified risk visibility. This post walks through both with real screenshots and KQL detections you can use today.

AI workloads are the new attack surface. Azure OpenAI endpoints are int...


Read full story