The Invisible Supply Chain, Part 1: Where AI Data Actually Comes From

Every AI model is, at its core, a direct product of its training data. Long before a system answers its first prompt or makes its first real-world prediction, decisions about data collection, sourcing, and processing have already permanently shaped its behavior. ...

July 9, 2026 · 3 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 2: Vulnerabilities You Can't Patch Out

In Part 1 we looked at how little organizations actually know about where their AI training data comes from. This time, we look at what happens once that unverified data gets baked directly into a model. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 3: How Model-Building Choices Introduce Risk

Parts 1 and 2 of this series covered the data going into a model. This time we look at the technical choices made while training and optimizing it — decisions that introduce their own, separate set of security trade-offs. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 4: The Fine-Tuning Inheritance Tax

So far this series has covered the data going into a model and the technical choices made while training it. Now: what happens when your organization doesn’t build a model at all, but fine-tunes someone else’s. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 5: Navigating the Black Box with Model Cards

The first four parts of this series covered where AI training data comes from, what gets permanently baked into a model, how training and optimization choices introduce risk, and how fine-tuning inherits all of it. This part covers a harder problem: you often can’t check any of it yourself. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 6: A Practitioner's Checklist

This series started with a simple idea: every AI model is a direct product of its training data, and most organizations deploying AI have no real visibility into what that data actually was. Over five parts, we traced that problem from raw data collection all the way through to the documentation that’s supposed to make it transparent. ...

July 9, 2026 · 3 min · Jason, Cyber Professional

ShinyHunters' Salesforce Campaign: Three Rounds, 1.5 Billion Records

ShinyHunters didn’t hack Salesforce. That distinction matters. Across three separate campaigns spanning mid-2025 through early 2026, the group — tracked by security researchers as UNC6040 and UNC6395 — systematically exploited how organizations configure, connect, and authenticate into Salesforce. The platform’s infrastructure was never the vulnerability. The integrations, the OAuth flows, and the guest user permissions were. ...

May 22, 2026 · 7 min · Logan