This site uses a cookie to remember your theme preference. No tracking or third-party cookies are used. See our Privacy Policy for details.

#RealTalk with Aaron Bregg Podcast Logo
  • Home
  • About
  • Learning
  • Search
  • Contact
  • Privacy

Categories

  • AI Agents (9)
  • AI Industry Watch (37)
  • AI Security (55)
  • MCP Security (3)
  • Non-Security (5)
  • Security Tools (1)
  • Threat Intelligence (1)

Tags

Agentic AI (12) AI Ethics (2) AI Governance (24) AI Infrastructure (6) AI Models (10) AI Regulation (9) AI Research (4) AI Security (22) Authentication (4) Authorization (3) Bug Bounty (1) Encryption (2) Enterprise AI (23) Future of Work (5) Healthcare AI (25) Malware (1) OWASP (1) Phishing (2) Secure Code (6) Social Engineering (2) Supply Chain Security (1) Vendor Risk Management (11) Zero Day (1)

Recent Posts

  • PolinRider: North Korea's Open Source Supply Chain Campaign and What It Means for Healthcare DevSecOps Jul 13
  • Claude Code Desktop: A Security Evaluation for Healthcare DevSecOps Programs Jul 11
  • The Mayo Clinic AI Governance Lawsuit: What the Eto Complaint Alleges and What It Means for Healthcare AI Programs Jul 10
  • Anthropic's Cyber Verification Program in Practice: From Approval to Real Defensive Work Jul 08
  • What the Scatter Spider Arrest Reveals About Windows Telemetry and PHI Risk on Clinical Workstations Jul 07

Theme

© 2026 Bregg Holdings LLC

#RealTalk with Aaron Bregg

Vendor Risk Management

11 articles

AI Security

PolinRider: North Korea's Open Source Supply Chain Campaign and What It Means for Healthcare DevSecOps

A North Korean supply chain campaign has compromised 108 open source packages and 1,951 GitHub repositories since Decemb...

Jul 13, 2026 13 min read
Read More
AI Security

Claude Code Desktop: A Security Evaluation for Healthcare DevSecOps Programs

Claude Code Desktop is the most capable AI-assisted development environment available in a desktop app today — and it sh...

Jul 11, 2026 13 min read
Read More
AI Industry Watch

The Mayo Clinic AI Governance Lawsuit: What the Eto Complaint Alleges and What It Means for Healthcare AI Programs

A former Mayo Clinic research director has filed a federal lawsuit alleging retaliation after raising AI compliance conc...

Jul 10, 2026 11 min read
Read More
AI Security

What the Scatter Spider Arrest Reveals About Windows Telemetry and PHI Risk on Clinical Workstations

A Scatter Spider member was caught partly through Windows Telemetry data. The same default-enabled collection mechanisms...

Jul 07, 2026 12 min read
Read More
AI Security

Claude Code's Hidden Fingerprint: A Security Analysis of the Steganographic Detection Mechanism

Anthropic's Claude Code was caught using steganographic Unicode encoding to silently fingerprint users routing through C...

Jul 05, 2026 12 min read
Read More
AI Industry Watch

Fable 5 Restored and the Jailbreak Severity Framework: Closing the Series, Opening the Governance Conversation

The 19-day Fable 5 suspension is over. But the more significant development is what emerged from it: a four-criteria jai...

Jul 01, 2026 11 min read
Read More
AI Security

One Phishing Email, Two Days, 1.4 Million Patients: The Xsolis Healthcare AI Breach

A single phishing email gave attackers a two-day window inside healthcare AI company Xsolis — long enough to expose 1.4 ...

Jun 29, 2026 9 min read
Read More
AI Industry Watch

Mythos 5 Partially Restored — US Government Authorizes Access for Critical Infrastructure Defenders

Fifteen days after the Commerce Department forced Anthropic to pull Mythos 5 and Fable 5 globally, the government has au...

Jun 27, 2026 9 min read
Read More
AI Industry Watch

Is This Now US Government Frontier AI Policy? The OpenAI GPT-5.6 Restriction and What It Means

The White House asked OpenAI to limit GPT-5.6's release to approved partners — the first preemptive government restricti...

Jun 26, 2026 10 min read
Read More
1 2
Next