2026 Verizon DBIR: What the Data Actually Means for Defenders

Every year, Verizon publishes the Data Breach Investigations Report, and every year the security community either over-indexes on a single headline or buries the thing in a drawer. The 2026 edition — the 19th — deserves neither treatment. Based on 31,000+ incidents and 22,000+ confirmed breaches across 145 countries, this is the largest dataset the DBIR has ever analyzed, and the findings have real operational implications for defenders at every level. ...

June 5, 2026 · 13 min · Logan

Canvas Breach Follow-Up: Instructure Pays the Ransom — And What That Means for All of Us

When I published my original piece on the Canvas breach back on May 9th, Instructure was publicly claiming the situation was contained. It wasn’t. Since then, ShinyHunters hit Canvas a second time through the same unpatched vulnerability, defaced login pages at hundreds of institutions, and ultimately extracted a ransom payment from Instructure, the amount of which has never been disclosed. As of May 12th, 2026, the story is closed. Sort of. Here’s everything that happened and what it means. ...

May 13, 2026 · 8 min · Jason, Cyber Professional