Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner

This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.”

SkySafe is a leader in drone detection, airspace intelligence, and drone forensics for security-conscious organizations.

The annual Golden Eagle Award recognizes excellence in system integration, architecture, engineering and/or construction (A/E/C) related to the safety and security of spectators, property and facility infrastructure.

Here, we talk with SkySafe’s Chief Revenue Officer Melissa Swisher about the winning submission and the evolving threat security teams are facing with increased drone operation.

Security Magazine: What does it mean to SkySafe to be recognized and honored with the Golden Eagle Award?

Melissa Swisher: Receiving the Golden Eagle Award from NCS4 and Security Magazine is a tremendous honor because it recognizes operational impact, not just innovation.

This award validates what we’re seeing across the market: drones have become a real and persistent security concern for campuses, stadiums, and public venues. Security teams need more than awareness — they need actionable intelligence and the ability to investigate incidents and hold operators accountable when necessary.

While the University of Illinois was the featured case study, the challenges they faced are representative of what we’re seeing across colleges and universities nationwide. We’re proud to support multiple higher education institutions that are proactively addressing airspace security, and this recognition reinforces the importance of that work.

Security: What problem was the University of Illinois trying to solve, and what made their environment challenging? What was the approach to overcoming those challenges?

“This award validates what we’re seeing across the market: drones have become a real and persistent security concern for campuses, stadiums, and public venues. Security teams need more than awareness — they need actionable intelligence and the ability to investigate incidents and hold operators accountable when necessary.”

Swisher: The University of Illinois is a large, high-activity campus with over 60,000 students, faculty, and alumni, and major sporting events drawing tens of thousands of spectators to campus weekly. The challenge was that with nearly 500 drone flights occurring on and around campus each month, campus authorities had no reliable way to distinguish between authorized drone activity and potential threats, and no means of holding violators accountable after the fact.

The environment compounded the challenge. A large, open campus with additional off-campus housing created significant airspace awareness challenges that traditional security measures were not designed to address. Drones can be launched from half a mile away and be over a crowded stadium in seconds. A single incident ultimately served as the catalyst for change. During a football game on campus, a drone breached restricted airspace during the third quarter and hovered within 10 feet of a SWAT officer stationed in an overwatch position, capturing images of critical security tactics. This exposed a major vulnerability: drones could not only endanger spectators and staff but also compromise operational security with unauthorized surveillance.

At the time, the university relied on manual drone monitoring methods, including visual line-of-sight and officer dispatch, which were labor-intensive and often ineffective. During this incident, 14 officers were deployed to locate the operator, ultimately without success.

Security: What did the threat picture look like over the course of the case study?

Swisher: SkySafe’s platform revealed the true scale of drone activity across the University of Illinois campus: more than 3,300 drone flights in a 12-month period. While the university initially relied on flight requests and approvals to manage activity, the data showed that much of the drone activity was uncoordinated and unannounced, creating persistent uncertainty around intent and risk.

Before SkySafe, the University of Illinois Police Department often deployed up to 15 officers to search for drone operators, with limited success. With real-time airspace intelligence on drone activity and operator location, most incidents can now be handled by just one or two officers, enabling faster, more efficient response while freeing personnel for other critical tasks.

The data made clear that drone activity was not occasional or isolated. It was a recurring operational challenge that required a systematic response.

Security: Did the system catch an incident? What did the response look like, and what could have happened without detection?

Swisher: During a sold-out football game at Memorial Stadium, SkySafe detected an unauthorized drone operating in the restricted airspace over the 50-yard-line. The platform identified the drone in real time, tracked its flight path, and pinpointed the operator’s location approximately half a mile from the stadium. Campus police were able to respond directly to that location within minutes and apprehend the individual.

What followed is what makes this case so significant. The operator was arrested and charged with reckless conduct, and the case held up in a court of law because SkySafe’s forensic evidence was irrefutable. Detailed flight records and geolocation data from the platform documented exactly where the drone had been and when, and who was operating it. Without that record, a detection alone would have produced an observation, but no consequence. With it, the university was able to make a prosecutable case that sent a clear message.

Security: How has the unauthorized drone situation evolved at large venues such as stadiums and arenas?

Swisher: The evolution has been dramatic.

A few years ago, most organizations viewed drones as an occasional nuisance. Today, they are a routine operational consideration for many security teams. Drones are more affordable, more capable, and more widely available than ever before, which has significantly increased the volume of activity around public venues and campuses.

What we’re seeing across colleges, universities, stadiums, and large public gatherings is that organizations are moving beyond asking whether drone activity exists and focusing instead on how they can effectively manage it.

The conversation has shifted from awareness to accountability. Security leaders want to know who is flying, where they are operating from, whether the activity is authorized, and what evidence exists if an incident requires investigation.

As major sporting events, concerts, and international events continue to grow in scale and complexity, airspace security is becoming an increasingly important component of overall venue security planning.

computer screens
Image courtesy of SkySafe

Security: What was it about this case study that stood out as one to submit for this award?

Swisher: What made the University of Illinois case study particularly compelling was that it demonstrated the complete operational value of airspace intelligence.

The university wasn’t simply detecting drones. They were able to identify activity in real time, locate operators, support investigations, improve resource allocation, and ultimately establish accountability when incidents occurred.

More importantly, the case illustrated a model that can be replicated across higher education. The challenges Illinois faced are not unique. Universities across the country are experiencing increasing levels of drone activity around campuses, athletic facilities, research centers, and special events.

The case study demonstrated how a security organization can move from reactive monitoring to proactive airspace management, which is exactly where the industry is heading.

Security: Anything else you would like to add?

Swisher: This award reflects a broader shift taking place across the security industry.

Organizations are increasingly recognizing that airspace is now an operational domain that requires the same level of awareness and intelligence as the physical environment. Colleges and universities have been among the most forward-thinking adopters because they manage complex environments that combine public events, research facilities, residential areas, and critical infrastructure.

We’re proud to partner with institutions that are leading the way and helping define best practices for the future of campus and venue security.

Ultimately, this recognition belongs not only to SkySafe but also to the security professionals who are embracing innovative approaches to keep their communities safe. Their willingness to evolve alongside emerging threats is what makes progress possible.

https://www.securitymagazine.com/articles/102433-eye-on-the-sky-skysafe-named-2026-golden-eagle-award-winner




Purple teaming: la difesa si misura una tecnica alla volta

Purple teaming nasce per chiudere un cortocircuito che la sicurezza offensiva si porta dietro da sempre. Il red team entra, dimostra che si poteva entrare, consegna un report. Il blue team lo legge, corregge qualcosa, e l’esercizio si esaurisce lì. Quello che quasi mai accade è la verifica sistematica di una domanda diversa e più utile: quando l’attaccante ha eseguito quella precisa tecnica, la difesa l’ha vista? L’ha bloccata? L’ha segnalata a chi doveva? Il purple teaming esiste per rispondere a questa domanda in modo misurabile, e per farlo trasforma una gara in una collaborazione.

Il nome trae in inganno, perché suggerisce un terzo team che si aggiunge agli altri due. Non è così. Il viola non è una squadra, è il colore che si ottiene mescolando il rosso e il blu, ed è esattamente questo il punto: attacco e difesa che lavorano insieme, nello stesso momento, condividendo in tempo reale ciò che l’uno fa e ciò che l’altro vede. La posta non è chi vince, ma quanto la difesa migliora, e di quanto esattamente.

Il problema del red contro blue

La modalità tradizionale tratta sicurezza offensiva e difensiva come avversari. Il red team ha successo se riesce a non farsi scoprire, il blue team se respinge l’attacco, e tra i due si apre una logica da partita in cui ciascuno ha interesse a non rivelare le proprie carte. È spettacolare, a volte utile, ma produce poco apprendimento strutturato. Alla fine resta un documento che elenca ciò che è andato male, senza garantire che la prossima volta andrà meglio, e senza dire con precisione quali capacità di rilevamento mancavano.

Il difetto è che l’informazione più preziosa, il momento esatto in cui una tecnica d’attacco passa inosservata, va sprecata. Se il difensore scoprisse in quell’istante che la sua regola non è scattata, potrebbe correggerla subito e riprovare. Nel modello a punteggio, invece, quella scoperta arriva settimane dopo, in forma di paragrafo in un report, quando il contesto è svanito. Il purple teaming recupera proprio quel momento, e lo mette al centro.

Non è un terzo team, è un modo di lavorare

In un esercizio di purple teaming le due parti operano in parallelo e si parlano. Il red team annuncia ed esegue una tecnica specifica. Il blue team osserva in diretta i propri strumenti, il Security Operations Center e le sue dashboard, e verifica se quella tecnica genera un segnale. Se il segnale c’è, si controlla che sia corretto, prioritario, azionabile. Se non c’è, si è trovata una lacuna, e la si affronta nel momento stesso in cui è visibile: si scrive o si corregge la regola di rilevamento, e il red team ripete la tecnica per confermare che ora viene intercettata.

È un ciclo stretto, fatto di esecuzione, osservazione, correzione e nuova prova. La differenza con il penetration test e con il red team classico non sta negli strumenti d’attacco, che sono gli stessi, ma nell’obiettivo: non dimostrare che si può entrare, ma misurare e aumentare la capacità di accorgersene. L’attacco diventa uno strumento diagnostico al servizio della difesa, non un fine in sé.

Purple teaming si misura su ATT&CK, una tecnica alla volta

Perché questo dialogo funzioni serve un linguaggio comune, e quel linguaggio esiste. Il framework MITRE ATT&CK cataloga le tattiche e le tecniche degli attaccanti in un vocabolario condiviso: dà al red team un repertorio di comportamenti da cui attingere per costruire gli scenari, e dà al blue team un modo per descrivere la propria copertura di rilevamento negli stessi termini. Quando entrambe le parti parlano di una tecnica con lo stesso identificativo, la verifica diventa puntuale: questa tecnica è coperta, quest’altra no.

È qui che il purple teaming smette di produrre opinioni e inizia a produrre misure. L’esito di un esercizio fatto bene non è un giudizio generico sulla maturità difensiva, ma una mappa di copertura tecnica per tecnica, in cui ogni voce è marcata come rilevata, bloccata o sfuggita. Quella mappa è anche il programma di lavoro della detection engineering, perché ogni casella scoperta è una regola da scrivere e una da testare. Il valore non è il numero di attacchi riusciti, ma il numero di tecniche che, dopo l’esercizio, la difesa è in grado di vedere e che prima le sfuggivano.

Dagli atomic test all’emulazione automatizzata

Per rendere ripetibile questo lavoro, la comunità ha prodotto strumenti che traducono le tecniche di ATT&CK in prove eseguibili. La libreria Atomic Red Team, aperta e mantenuta da una vasta comunità di professionisti, raccoglie test piccoli e autonomi, gli atomics, ciascuno mappato a un identificativo di tecnica, per esempio T1059 per l’abuso di interpreti di comandi e script o T1003 per il dumping delle credenziali dal sistema operativo. Ogni test gira in pochi minuti e richiede una configurazione minima, così il difensore può verificare una singola tecnica senza allestire un’intera campagna. Sul versante dell’automazione completa, piattaforme di emulazione avversaria come MITRE Caldera orchestrano sequenze d’attacco allineate ad ATT&CK e restituiscono quali controlli hanno funzionato e quali no. È l’evoluzione del purple teaming nella forma della breach and attack simulation, dove le prove non si fanno una volta l’anno ma in modo programmato e continuo.

Dall’esercizio alla pratica continua

Il limite del purple teaming inteso come evento è lo stesso di qualunque collaudo isolato: fotografa un istante. Un’organizzazione che valida la propria copertura una volta e poi cambia un sistema, aggiorna uno strumento o modifica una regola torna a non sapere cosa rileva davvero. Per questo la direzione matura è la pratica continua, in cui le tecniche più rilevanti vengono rieseguite con regolarità e ogni regressione, una regola che smette di scattare dopo un aggiornamento, emerge subito invece che durante il prossimo incidente.

In questa forma il purple teaming smette di essere un appuntamento e diventa un processo, intrecciato con l’automazione della sicurezza e con il lavoro quotidiano del centro operativo. L’attacco simulato alimenta la scrittura dei rilevamenti, i rilevamenti vengono verificati da nuovi attacchi simulati, e la copertura cresce in modo documentato anziché per intuizione.

Il punto di arrivo è un cambio di mentalità più che di strumenti. Finché sicurezza offensiva e difensiva restano due squadre che tengono il punteggio, il risultato è un verdetto: si è entrati, oppure no. Quando diventano un’unica funzione che misura e migliora, il risultato è una capacità: sapere, tecnica per tecnica, cosa si rileva e cosa ancora sfugge, e vedere quel divario restringersi prova dopo prova. È questa la promessa concreta del purple teaming, e spiega perché, in un panorama in cui gli attaccanti riusano le stesse tecniche per anni, misurare la propria difesa una tecnica alla volta è più utile di qualunque esercitazione vinta o persa.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/cyber-security/purple-teaming/




Cyberattack Halts Coca-Cola’s Fairlife Productions

The Coca-Cola Company stated a dairy company it owns (fairlife, LLC), has suspended production in the United States due to a cyberattack.

After a user gained unauthorized access to parts of its systems, including production-related operations, the organization was forced to temporarily suspend operations. 

Outside cybersecurity experts have been called upon by the organization to assist in an investigation. At this time, there is no evidence that product quality or safety has been impacted. 

Canadian operations remain ongoing. Systems and operations in the U.S. are in the process of restoration. 

https://www.securitymagazine.com/articles/102441-cyberattack-halts-coca-colas-fairlife-productions




Hugging Face Confirms Data Breach Caused by Autonomous AI Agent

Hugging Face, a host platform for AI models and datasets, confirmed it had experienced a data breach. Furthermore, the organization asserted the breach had been carried out entirely by an AI agent. 

“We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services,” the platform stated in a post regarding the matter. “We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean.” 

According to the organization’s statement, the intrusion began with a malicious dataset exploiting two code-execution paths in the platform’s dataset processing so code could be run on a processing worker. The attack then rose to node-level access, enabling the attacker to harvest cluster and cloud credentials before shifting laterally into multiple internal clusters. 

The statement asserts that the attack was carried out by an “autonomous agent framework,” enacting “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” 

“This matches the ‘agentic attacker’ scenario the industry has been forecasting,” the statement warns. 

Rohit Valia, CEO of Tumeryk, comments, “Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”

https://www.securitymagazine.com/articles/102442-hugging-face-confirms-data-breach-caused-by-autonomous-ai-agent




Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software.

Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money to grow its engineering and go-to-market teams. 

Neo’s platform serves as a control layer that governs AI agents, AI-enabled applications, and traditional software across enterprise environments. 

Security operations teams can use the system to maintain a continuous catalog of active elements, such as agents, models, extensions, and MCP servers. Additionally, the solution evaluates these discovered assets to identify excessive access privileges and configuration vulnerabilities.

The product includes real-time attribution mechanisms that trace individual software actions directly back to the originating human user, automated agent, or specific application identity. It can natively enforce granular policies for tool calls, data movement, agentic workflows, and API access.

Security teams can restrict unauthorized activities or pause suspicious operations for manual review.

Advertisement. Scroll to continue reading.

Neo was founded by Nick Warner, Shlomi Salem, and Eran Shirazi. Warner serves as the company’s CEO, having previously held leadership roles at SentinelOne (president and COO), Cylance, McAfee, and Forepoint. 

Salem (CPO) previously led detection engineering at SentinelOne, while Shirazi (CTO) co-founded customer experience firm EasySend.

“AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms, and traditional applications, giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions,” said Warner. “Neo gives enterprises the real-time control layer they need to understand what agentic software can do, govern how it behaves, and secure adoption without slowing down the business.”

Related: Beacon Security Raises $13 Million for Security Data Platform

Related: Risk Ledger Raises $32 Million in Series B Funding

Related: Oak Emerges From Stealth Mode With $60 Million in Funding

https://www.securityweek.com/neo-emerges-from-stealth-with-100m-to-control-and-secure-enterprise-ai-software/




SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity.

SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild.

Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 secure remote access appliances. SonicWall has made available hotfix releases to address the security holes.

Volexity, which assisted the vendor’s investigation into the attacks, attributed the exploitation of the zero-days to a threat actor it tracks as UTA0533. 

The security firm believes exploitation started as early as June 22.

The company on Friday shared IoCs and other technical details related to the attacks, but it has not linked UTA0533 to any known threat actor and the group’s motivation remains unclear. However, based on Volexity’s description, the attack appears more consistent with state-sponsored APT activity rather than a profit-driven cybercrime operation.

Advertisement. Scroll to continue reading.

Once the attackers compromised the targeted SonicWall appliances, they deployed custom malware named KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail, and an open source proxy named Suo5.

“With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances,” Volexity said. 

The security firm added, “Although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.”

CISA has added CVE-2026-15409 and CVE-2026-15410 to its KEV catalog, which currently includes 17 flaws affecting SonicWall products.

Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Related: Splunk, Zoom Patch Critical Vulnerabilities

Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/




Pay up or not? Ransomware surge has victims facing tough choices

Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cyber security group Sophos, while the median amount demanded is rising.

Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for example, the government is advancing plans to prohibit public sector bodies and critical national infrastructure groups—including the National Health Service, local councils and schools—from making payouts.

The potential veto comes as ransomware hackers have become more advanced and meticulous in their targeting of companies, particularly vulnerable small and medium-sized businesses, over time.

“In 2026, the ransomware landscape has evolved into a highly sophisticated, corporate-style ecosystem,” says Haydn Brooks, chief executive of supply chain security group Risk Ledger. “While ransomware groups operate like smart B2B operations to ensure data return, the legal and sanction risks of paying are at an all-time high.”

This has been powered by the rise of malicious AI hacking tools such as WormGPT, FraudGPT and BruteForceAI, according to Dave Spillane, systems engineering director at Fortinet, who notes that confirmed ransomware victims rose 389 percent year-on-year in 2025, from around 1,600 in 2024 to 7,831 globally.

“In the time it would have previously taken to commit one ransomware attack, hackers can now target four separate organizations simultaneously,” he says.

“The cost per attack has dramatically decreased, commoditising sophisticated attacks, whereas the cost to defend is increasing,” agrees Shashi Kiran, chief marketing officer of tech group Nile. “What required nation states earlier can be accomplished by individuals with half-baked skills leveraging the power of AI.”

https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/




OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A vulnerability in OpenSSL could allow attackers to cause a server’s memory to be exhausted before any security handshake, Okta’s red team discovered.

Referred to as HollowByte, the denial-of-service (DoS) bug could be triggered via a malicious payload of only 11 bytes that declares a larger incoming message body to trigger a buffer pre-allocation that is not immediately freed.

HollowByte existed because older OpenSSL iterations pre-allocated receive buffer sizes based on the incoming message body length declared in the handshake message’s 4-byte header.

The pre-allocation occurred before any data arrived, and an attacker could send an 11-byte payload to trigger an unvalidated buffer allocation of up to 131 KB.

“The worker thread then blocks, waiting indefinitely for data that will never arrive,” Okta explains.

Additionally, because the GNU C Library (glibc) retains small-to-medium memory allocations for potential reuse and does not immediately return them to the OS when a connection drops, although OpenSSL frees the buffer, multiple successive payloads could be sent to exhaust the server’s memory.

Advertisement. Scroll to continue reading.

“By launching waves of connections with randomized claimed sizes, an attacker prevents the allocator from reusing those freed chunks,” Okta explains.

“Even after the attacker disconnects, the server remains permanently bloated. The only way to reclaim that memory is to terminate the process,” it adds.

In real-world testing, a 1 GB RAM system became unresponsive after 547 MB of memory was fragmented and frozen.

On a 16 GB RAM system, “the attack successfully locked up 25% of the system’s total memory while staying safely under the connection ceiling, meaning standard connection-limiting defenses won’t stop it,” Okta says.

Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, PostgreSQL, and other types of applications, servers, runtimes, and databases that use OpenSSL are impacted unless they upgrade to a patched version of the open source library.

Patches for HollowByte were silently included in OpenSSL version 4.0.1 and silently backported to versions 3.6.3, 3.5.7, 3.4.6, and 3.0.21. Now, the library increases the buffer size as bytes actually land and no longer trusts the handshake header for buffer growth.

Related: Chrome 150 Update Patches Severe Memory Safety Bugs

Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

Related: SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/




New Index Tracks Material Breaches — And Refuses to Add Up the Losses

A longtime cybersecurity executive has built a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist.

The tracker was created by Richard Bird, who is currently Chief Strategy and Chief Security Officer at enterprise AI governance company Singulr AI. He previously held leadership roles at JPMorgan Chase and several cybersecurity companies. 

Unrelated to his role at Singulr AI, Bird is an author, and in preparation for his upcoming book — Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It — he has launched a new project named The Hacker in a Hoodie (HIH) Index. 

The core of the site is a pair of ledgers that update on what Bird describes as a daily or near-daily basis, pulled by pollers and tracers he built and runs himself. 

The first ledger draws from SEC EDGAR, the agency’s public filing database, tracking the 8-K disclosures that public companies are required to file when they experience a material cyber incident — a requirement that has existed only since 2023. The second ledger is based on news articles and companies’ own statements.

The data arrives as raw, inconsistent text, with some entries naming a dollar loss while most don’t. Bird’s ledger organizes those scattered records into one running list.

Advertisement. Scroll to continue reading.

At the time of writing, the index contains information on more than 100 incidents. The most current entries cover data breaches reported by Coca-Cola’s Fairlife, Centers Lab, Mount Royal University, and Accenture.  

The HIH Index grades every entry by how solid its sourcing is: a primary SEC filing counts as ‘verified’, a company’s own statement as ‘attested’, and a news report as ‘inferred’. That grading lets a reader tell at a glance how much weight a given entry can actually carry.

Separate from both ledgers, the site includes a static reference chart that pulls annual figures from the FBI’s Internet Crime Complaint Center (which shows nearly $20.9 billion in reported losses for 2025) and IBM’s Cost of a Data Breach report (which shows an average of $4.44 million per breach). 

These reports provide context for the project’s argument. They show that per-incident cost has barely moved in a decade, even as total reported losses have compounded at roughly 35% a year.

“This means only one thing — the hackers aren’t making more money from the same number of victims,” Bird told SecurityWeek. “More companies are failing (way more) at cybersecurity every year and the bad guys are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed at these companies.”

He added, “The [upcoming] book, and the index, are not pointing fingers of blame. What we’ve built in cybersecurity is rational. But it is rational based on the wrong data and inputs — we measure activity, we don’t measure performance and outcomes.”

Bird’s case against summing the HIH Index data is straightforward: most of the ledger’s entries are marked ‘not yet quantified,’ and the ones that do carry a figure come from different evidence tiers — a verified dollar loss in an SEC filing isn’t the same as an inferred estimate drawn from a news report. Treating those as interchangeable and adding them together would produce a number that looks precise but is not backed by anything solid. 

He points to the industry’s favorite trillion-dollar cybercrime estimate, a controversial Cybersecurity Ventures projection, as exactly the kind of number his project aims to avoid manufacturing.

“Summing the numbers creates a myth — it is no longer data; it becomes a prediction at best and a forecast at worst,” Bird explained. “The losses are so grossly underreported that if I took that sensationalist approach, I’d be creating another version of the same problem. A bunch of guessing that is perceived as being better but only because it has more citations.”

What makes the ledgers useful isn’t the total — it’s the ability to check. A reporter or analyst can look up what a specific company actually disclosed, how the filing was worded, and what evidence grade it carries. In an industry where cyber loss reporting leans heavily on marketing-driven estimates, having a citable, source-graded reference to check claims against fills a gap that has largely gone unfilled.

Bird maintains the entire project alone — no editorial team, no outside data vendor, just the scrapers he built to keep both ledgers current. He is also upfront about the dataset being young: the SEC requirement it’s built on is relatively new, and he draws a direct comparison to Troy Hunt’s Have I Been Pwned data breach notification service, which also started small and grew because there was nowhere else to look.

That absence is the point he’s really making. Everything else in a company gets measured in dollars, except cybersecurity, which Bird says has been treated as overhead instead of a tracked outcome. In his words:

“Business keeps score in dollars, governments keep score in dollars, consumers keep score in dollars — cybersecurity is the only business function that isn’t measured in dollars from a performance perspective. It’s treated as a ‘cost of business’. There is only one other corporate ‘cost of business’ in the enterprise world — whether it is large, medium or small businesses. And that is taxes. We built cybersecurity as a tax, not as a value-added business function. The entire industry and practice has created an ecosystem over the last 30 years that not only emphasizes that truth, it actually rewards the continuation of the flawed model.”

Related: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk

Related: New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications

https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/




Ernst & Young Data Breach Affects Personal, Financial Information

Professional services giant Ernst & Young (EY) has started notifying its clients that their personal and financial information was compromised in a data breach.

The incident was discovered on April 23 and involved a third-party service management platform that EY uses to support tax-related work it performs on behalf of its clients.

“Support tickets submitted through the platform may include documents containing client tax information,” the company wrote in a notification letter sent to clients, a copy of which was filed (PDF) with the California Attorney General’s Office.

After identifying anomalous activity on the platform, EY activated incident response and began remediation and recovery efforts. It also engaged an independent cybersecurity firm to investigate the nature and scope of the attack.

The hackers, it says, had access to the compromised platform between March 28 and April 12, and downloaded documents of EY clients.

Personal and financial information contained within those documents includes names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used to prepare tax filings, EY told the Texas AGO.

Advertisement. Scroll to continue reading.

The company says it is not aware of any misuse or further exposure of the affected clients’ personal information, but is providing them with two years of free credit monitoring, identity monitoring, and identity restoration services.

EY has not shared details on how the attack occurred, nor on the threat actor responsible for it, and no known ransomware or extortion group appears to have claimed responsibility for the incident.

SecurityWeek has emailed Ernst & Young for additional information on the data breach and will update this article if the company responds.

Related: Hugging Face Hacked in Autonomous AI Attack

Related: Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims

Related: Centers Laboratory Data Breach Affects 540,000 Individuals

Related: 12 Million Impacted by Data Breach at Japanese Telco KDDI

https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-information/