It’s the last Thursday of the month, which means it’s the day I post something completely different. Included below are a few topics and articles that I found interesting this month.
DEF CON
This story from a Delta flight from Las Vegas to Atlanta following DEF CON doesn’t necessarily bring up a new concept in hacking, though the timing definitely leaves a lot to be desired. It would seem doing something illegal while on a plane with no exit strategy isn’t the smartest idea, unless their name is DB Cooper.
Still, the story allowed me to reminisce about attending DEF CON in 2017 with some coworkers, which was an experience both during and after-hours. Most of the conference was over my head, but I did learn how to pick locks and still have a lock picking set stored somewhere.

Apple
Apple will send a push notification to your phone if it detects “mercenary spyware attacks” based on who you are or what you do. This is a feature Apple has had in place since 2001, but popped into the mainstream once again this past month.
Security awareness training (including phishing, vishing, and smishing) usually recommend being cautious when an email, text, or phone call comes with a sense of urgency or pressure, so this would require some thought before taking next steps if it popped on my screen.
Infrastructure
Bear with me as I go in a little circle here regarding the cyber attacks on water infrastructure in various states.
Chesterton’s Fence is “the principle that you should not remove or change a rule, system, or object until you understand why it was put there in the first place”. I learned about this principle recently, mostly because it applies to so many things happening around us.
With my prior employer, an aspect of my job responsibilities was to complete IT risk and general controls assessments for local (small) municipal and public sector entities. Something I always had to keep in mind while performing these assessment was their resource limitations, which directly affected what types of recommendations could be made.
The Cybersecurity and Infrastructure Security Agency (CISA) is a federal agency under the Department of Homeland Security (DHS) responsible for protecting the nation’s critical infrastructure and cyber defenses. CISA provides additional support for local entities, including infrastructure, that don’t have the resources to do everything on their own.
CISA’s staff dropped from roughly 3,300 to about 2,389 employees last year (2025), which is a loss of about a third of the agency. Proposed budget plans for 2027 target the elimination of ~900 additional positions.
Job cuts at CISA, limited resources at the local level, and constantly increasing cyber threats is a recipe for disaster and could make cyberattacks on our infrastructure more common and potentially successful.
This is a long winded way of noting the job cuts at CISA are not a good idea.