Sign in

Jim Donahue

@jimdonahue-cyber.bsky.social
301 followers 26 following 98 posts

My work account, focused on cybersecurity. I'm the former managing editor, content operations, at Dark Reading, part of Informa TechTarget. I'm currently freelancing there.

PostsRepliesMedia
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 24/09/2026
3 Cyber Threats That Defined the Summer of 2026 www.darkreading.com/cyberattacks-da… #DRTheEdge
darkreading.com
3 Cyber Threats That Defined the Summer of 2026
This Reporters' Notebook video discusses AI agents breaching Hugging Face, Fairlife's ransomware attack, and threat actors targeting a dozen water systems.
011
Reposted by Jim Donahue
Eric Geller @ericjgeller.com · 24/09/2026
CISA has released its election security plan for the midterms. It's nothing exciting: summaries of how election infrastructure works, what cyber/physical vulnerabilities exist, and what services CISA offers, plus a push for information sharing. www.cisa.gov/sites/defaul...
294
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 23/09/2026
Paying a ransom doesn't necessarily mean stolen data disappears. The ShinyHunters-Cl0p feud is a stark example of why: Once data is outside of an organization's control, it can potentially be stolen again, resold, exposed, or used for another round of extortion. bit.ly/4hlkf83
bit.ly
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
ShinyHunters breached rival ransomware gang Cl0p's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 23/09/2026
Google, Microsoft, and xAI argue for a potential pause in AI deployment. Still, enterprises need the time too: Many businesses now have AI policies, best practices & a defined risk appetite, but "what they often lack is a way to enforce and verify those policies in practice." bit.ly/4yIMfJG
bit.ly
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment underscore AI risks, both large AI labs and regular businesses are searching for better way to keep control and be secure.
011
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 18/09/2026
China's FamousSparrow APT Spies on US Politics in Latin America bit.ly/4AmcBTt by Nate Nelson #DRGlobal
darkreading.com
China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
011
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 17/09/2026
AI Security Spending Jumps as Fear Outpaces Proof of Value bit.ly/3VlmlgN by Jai Vijayan
darkreading.com
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 16/09/2026
Fighting Your Dragons Through Tough Tech Times bit.ly/4h4SHUg Cybersecurity industry vet Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns in our latest Dark Reading Confidential podcast.
darkreading.com
Finding Hope During Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and shares advice on building connections during tech industry downturns.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 10/09/2026
Patch Tuesday Sets Another Record With 974 CVEs In 2022, Microsoft disclosed and patched 917 total CVEs across 12 Patch Tuesdays. On Tuesday, the software giant fixed a record 974 vulnerabilities for its September Patch Tuesday alone. Is this the new normal? bit.ly/4xPfUkC
darkreading.com
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 31/08/2026
Bug bounty report volume is exploding. What happens when vulnerability discovery becomes easier, faster, and more abundant? That's the question behind Alexander Culafi’s latest reporting on the "vulnpocalypse" and the changing economics of bug bounties. bit.ly/4gAP2gR
bit.ly
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge of AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 27/08/2026
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026: bit.ly/4A0biK3 #DRTheEdge
darkreading.com
Agentic AI Risks, CVE Program Concerns Permeate Black Hat 2026
This installment of the Reporters' Notebook video series discusses several topics such as AI's effects on vulnerability reporting and security research.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 27/08/2026
Red Flags That Expose Fake North Korean IT Workers: www.darkreading.com/insider-threats… by Alexander Culafi
darkreading.com
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 26/08/2026
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month: bit.ly/3SWGjh1 by Elizabeth Montalbano
darkreading.com
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
The AitM service lowers the barrier to entry for actors to create phishing attacks that steal more than just user credentials.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 24/08/2026
The Vulnerability Gap: Why Discovery Is Outrunning Repair bit.ly/4qwYmXw Commentary by Christopher Robinson, Chief Security Architect, Open Source Security Foundation
darkreading.com
The Vulnerability Gap: Why Discovery Is Outrunning Repair
AI is discovering more vulnerabilities, faster, and the entire cybersecurity community must pitch in to respond.
001
Reposted by Jim Donahue
Eric Geller @ericjgeller.com · 11/08/2026
One of the biggest topics at last week's Black Hat and @defcon.bsky.social conferences was the future of the CVE Program, which assigns vulnerability IDs that are used all over the place. My new story wraps together everything we heard from key CVE figures: www.cybersecuritydive.com/news/cve-pro...
1179
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 03/08/2026
As we head into Black Hat USA 2026, hear the voices that have been sounding the alarm for two decades, including: ✓ Bruce Schneier ✓ Katie Moussouris ✓ Rich Mogull ✓ Robert "RSnake" Their favorite Dark Reading columns from the past 20 years are still relevant today. bit.ly/45COi5A
bit.ly
Cyber Pioneers Ponder Past as Prologue
Robert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier consider whether columns they penned have stood test of time.
021
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 28/07/2026
AI models and agents routinely plow through guardrails, leaving companies the task of ensuring they are behaving well. "[N]o matter how good the model is, you cannot yet trust their guardrails 100 percent." — Nico Waisman, CISO, XBOW bit.ly/4fByFzQ By Robert Lemos
bit.ly
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 22/07/2026
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face: bit.ly/4vGQB28 by Elizabeth Montalbano
darkreading.com
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
011
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 22/07/2026
A quarter of security executives considered leaving their job in the past 12 months, as securing AI in the workplace raises stress: "[S]uddenly, lower-skilled attackers have access to new tools that allow them to do a lot of damage," says Michael Fanning, CISO at Splunk. bit.ly/3R50Jnm
bit.ly
CISOs Feel the Heat Over AI Risk
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
011
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 20/07/2026
Inc Ransomware Exploits SonicWall SMA Zero-Days: bit.ly/4wTBX8R by Nate Nelson
bit.ly
Inc Ransomware Exploits SonicWall SMA Zero-Days
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
002
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 20/07/2026
The White House's new Gold Eagle clearinghouse targets a real vulnerability coordination gap. Whether it can solve the remediation challenge is another question. bit.ly/4bIyKR9 by Alexander Culafi
bit.ly
Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 20/07/2026
Cybersecurity Keeps Events 'Uneventful': bit.ly/45faD96 Commentary by Olga Polishchuk, ZeroFox
darkreading.com
Cybersecurity Keeps Events 'Uneventful'
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with enormous security demands.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 16/07/2026
🌍✨ Dark Reading just launched European cybersecurity coverage! From Germany to Greece, France to Italy—we're bringing you threat intelligence that understands YOUR unique challenges. Find out why Europe's cyber landscape needs its own lens 👀 #CyberDefense #Europe #InfoSec bit.ly/3Q3ERrH
bit.ly
Dark Reading | Europe
Breaking cybersecurity news, news analysis, commentary, and other content from Europe.
011
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 15/07/2026
In our latest episode of Reporters' Notebook, Sharon Shea from TechTarget Cybersecurity talks about how much information is at risk when schools are targeted by threat actors. Check out the full episode here: bit.ly/4vtf1MF
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 16/07/2026
At 622 CVEs, Microsoft's July 2026 Patch Tuesday is the biggest ever. But the real story is how AI-driven vulnerability discovery is forcing organizations to rethink how they prioritize and deploy patches. bit.ly/4po2o3N by Jai Vijayan
bit.ly
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 16/07/2026
European nations were already looking to reduce their reliance on American tech companies, but the US government's ban on Anthropic's frontier models threw petrol on the tech sovereignty fire. bit.ly/4vBB6bT by Rob Wright
bit.ly
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
The US government's restrictions on Anthropic frontier models intensifies calls in the UK to reduce reliance on US tech, with cyber implications.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 16/07/2026
"I want to change the law," Jen Ellis told Rapid7’s then-CEO Corey Thomas. That statement changed the relationship between industry and government. Check out Dark Reading’s Security Pro File by Ericka Chickowski | Jen Ellis: Connecting Cyber Community With Political Machinery bit.ly/4aX2oSA
bit.ly
Jen Ellis: Connecting Cyber Community with Political Machinery
On the heels of recent honors for her contribution to cyber policy, Jen Ellis looks back at the events that shaped her advocacy for security researchers.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 14/07/2026
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics: bit.ly/44uD1Us by Elizabeth Montalbano
darkreading.com
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 14/07/2026
Weak Security Continues to Fuel Russian Cyberattacks: bit.ly/3RcrhD6 by Jai Vijayan
darkreading.com
Weak Security Continues to Fuel Russian Cyberattacks
In a first, the UK and the EU jointly imposed sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.
012
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 14/07/2026
Manage Vendor Risk in a Few Practical Steps: bit.ly/4fzxDpf Commentary by Daniel Nutkis, HITRUST
darkreading.com
Manage Vendor Risk in a Few Practical Steps
Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.
001
Reposted by Jim Donahue
Dark Reading @darkreading.bsky.social · 14/07/2026
Engineers are using Claude Mythos and GPT-5.5 to build defenses against futuristic AI cyberattacks. Along the way, they're also building the tools hackers will use to carry out those attacks. bit.ly/4wJvBsH by Nate Nelson
darkreading.com
'Yellow Teams' Are Defining the Future of AI Security
In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.
001
Jim Donahue @jimdonahue-cyber.bsky.social · 07/05/2026
I retired this acct when I ... well, retired. But I wanted to share this story about Dark Reading's 20th anniversary.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 27/08/2025
I'm retiring as of tomorrow, so this work account will be going dark. (It seems likely I'll do some freelance work in 2026, so I'm not shutting down the acct. But I'm taking it easy a few months.) I do have a personal account here, but it seems weird to post the link. Feel free to DM me, though.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 19/08/2025
New on @darkreading.bsky.social, commentary by Liad Cohen and Eyal Paz, OX Security: "By addressing these risk vectors, organizations can continue leveraging GitHub's innovation while protecting against the sophisticated supply chain attacks targeting our interconnected software ecosystem."
darkreading.com
10 Major GitHub Risk Vectors Hidden in Plain Sight
By addressing these overlooked risk vectors, organizations can continue leveraging GitHub's innovation while protecting against sophisticated supply chain attacks targeting interconnected software.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 18/08/2025
New on @darkreading.bsky.social, commentary by Aditya K. Sood, VP of Security Engineering & AI Strategy, Aryaka: "Today's RATs don't just exploit technical vulnerabilities. They also take advantage of the blind spots created by how enterprise architects establish their security environments."
darkreading.com
How Evolving RATs Are Redefining Enterprise Security Threats
A more unified and behavior-aware approach to detection can significantly improve security outcomes.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 15/08/2025
New on @darkreading.bsky.social, commentary by Ivanti's Field CISO Mike Riemer: "When security becomes part of the development culture rather than an external constraint, teams start thinking about security implications naturally as they build features."
darkreading.com
Using Security Expertise to Bridge the Communication Gap
Cybersecurity-focused leadership delivers better products and business outcomes.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025
New on @darkreading.bsky.social, commentary by Ofri Ouzan, Security Researcher & Advocate, JFrog: CVE scoring systems "often fail to account for the unique context of each organization's environment. As a result, teams risk focusing on theoretical risks while genuine threats may be overlooked."
darkreading.com
The Critical Flaw in CVE Scoring
With informed decision-making, organizations can strengthen their overall resilience and maintain the agility needed to adapt to emerging threats, without sacrificing innovation or productivity.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025
New on @darkreading.bsky.social, commentary by Lane Sullivan, Chief Information Security & Strategy Officer, Concentric AI: "Being a CISO today is a balancing act of strategic leadership, financial literacy, technical expertise, and human connection, regardless of [company size]."
darkreading.com
Redefining the Role: What Makes a CISO Great
Security is everyone's responsibility, but as a CISO, it starts with you.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025
New on @darkreading.bsky.social, commentary by Melina Scotto, Founder, Mastin & Associates: "Consider securing AI as your next career opportunity to transform challenges into a strategic advantage and build cyber resilience in a rapidly changing, AI-enabled, digital world."
darkreading.com
Will Secure AI Be the Hottest Career Path in Cybersecurity?
Securing AI systems represents cybersecurity's next frontier, creating specialized career paths as organizations grapple with novel vulnerabilities, regulatory requirements, and cross-functional deman...
000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025
New on @darkreading.bsky.social, commentary by Pritesh Parekh, CISO, PagerDuty: "In an era where cyber threats are increasingly sophisticated and pervasive, the importance of post-incident security reviews cannot be overstated." Get tips on organizing your own reviews.
darkreading.com
Building the Perfect Post-Security Incident Review Playbook
By creating a safe environment for open discussion, prioritizing human context alongside technical data, and involving diverse stakeholders, organizations can turn security incidents into accelerators...
000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025
New on @darkreading.bsky.social, commentary by Trend Micro's Jon Clay: "While the cybercriminal underground has professionalized and become more organized in recent years, threat actors are, to a great extent, still using the same attack methods today as they were in 2020."
darkreading.com
Why the Old Ways Are Still the Best for Most Cybercriminals
While the cybercrime underground has professionalized and become more organized in recent years, threat actors are, to a great extent, still using the same attack methods today as they were in 2020.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025
Get the latest news from Black Hat this week. www.darkreading.com/keyword/blac...
darkreading.com
Black Hat News
Black Hat News
000
Reposted by Jim Donahue
Eric Geller @ericjgeller.com · 30/07/2025
Scoop: CISA's contract with ICF has expired, reducing the JCDC's contractor workforce from 100+ to just 10. CISA can use emergency money & 2-week extensions to keep those 10 around, but only through Sept. Other contracts also caught up in huge backlog. www.cybersecuritydive.com/news/cisa-jo...
21913
Jim Donahue @jimdonahue-cyber.bsky.social · 30/07/2025
New on @darkreading.bsky.social, commentary by Alisdair Faulkner, Darwinium: "We must accept that malicious agents will often appear legitimate — and gain access. Defending against them requires speed, but not at the expense of paralyzing online commerce."
darkreading.com
How to Spot Malicious AI Agents Before They Strike
The rise of agentic AI means the battle of the machines is just beginning. To win, we'll need our own agents — human and machine — working together.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 30/07/2025
New on @darkreading.bsky.social, commentary by Roger Cressey, Mountain Wave Ventures: "As we reflect on the anniversary of the largest outage in IT history, organizations everywhere need to make an active effort to ... create a more robust and resilient cyber ecosystem moving forward."
darkreading.com
The CrowdStrike Outage Was Bad but Could Have Been Worse
A year after the largest outage in IT history, organizations need to make an active effort to diversify their technology and software vendors and create a more resilient cyber ecosystem moving forward...
000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025
New on @darkreading.bsky.social : "By tying security investments to measurable outcomes — like reduced breach likelihood and financial impact — CISOs can align internal stakeholders and justify spending based on real-world risk." Commentary by Kara Sprague, CEO, HackerOne
darkreading.com
Securing the Budget: Demonstrating Cybersecurity's Return
By tying security investments to measurable outcomes — like reduced breach likelihood and financial impact — CISOs can align internal stakeholders and justify spending based on real-world risk.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025
New on @darkreading.bsky.social: "Many CISOs still find themselves speaking a technical language that fails to resonate with other leaders. Technical terms often fall flat in boardrooms more concerned with revenue growth and brand reputation." Commentary by Ashley Rose, Living Security
darkreading.com
Translating Cyber-Risk for the Boardroom
When security leaders embrace this truth and learn to speak in the language of leadership, they don't just protect the enterprise, they help lead it forward.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025
New on @darkreading.bsky.social: "Today's insider threats aren't lone wolves acting out of spite — they're pawns in the hands of sophisticated, organized criminal networks." Commentary by Rob Juncker, Mimecast
darkreading.com
How Criminal Networks Exploit Insider Vulnerabilities
Criminal networks are adapting quickly, and they're betting that companies won't keep pace. Let's prove them wrong.
000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025
New on @darkreading.bsky.social: "Agentic AI could be a disaster for authorization systems in software-as-a-service (SaaS) platforms as we know them today. But it doesn't have to be, if security and IT teams address the challenges proactively." Commentary by Josh Lemos, GitLab. chaos
darkreading.com
3 Ways Security Teams Can Minimize Agentic AI Chaos
Security often lags behind innovation. The path forward requires striking a balance.
000
Reposted by Jim Donahue
Eric Geller @ericjgeller.com · 27/06/2025
My new story about the U.S. government’s fraying partnerships with critical infrastructure operators is packed with new reporting, but there’s a lot more that I couldn’t fit into the story. Here are some more details from my interviews over the past few weeks about where things stand…
34420