News

Breach of Confidence – 27 March 2026

  • None--securityboulevard.com
  • published date: 2026-03-27 00:00:00 UTC

None

<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png"><img fetchpriority="high" decoding="async" width="1024" height="535" data-attachment-id="4322" data-permalink="https://javvadmalik.com/2026/03/27/breach-of-confidence-27-march-2026/breach-of-confidence-banner/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png" data-orig-size="1200,628" data-comments-opened="0" data-image-meta='{"aperture":"0","credit":"","camera":"","caption":"","created_timestamp":"0","copyright":"","focal_length":"0","iso":"0","shutter_speed":"0","title":"","orientation":"0","alt":""}' data-image-title="breach-of-confidence-banner" data-image-description="" data-image-caption="" data-medium-file="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=300" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=1024" src="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=1024" alt="" class="wp-image-4322" srcset="https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=1024 1024w, https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=150 150w, https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=300 300w, https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png?w=768 768w, https://javvadmalik.com/wp-content/uploads/2026/03/breach-of-confidence-banner.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px"></a></figure><p class="wp-block-paragraph">I’ve been watching my phone battery go to 37% lately and it’s giving me anxiety even though I know I can make it through the day. This is why I don’t think I’ll ever be able to live with an electric car.</p><p class="wp-block-paragraph"><strong>The Scanner That Scanned Itself</strong></p><p class="wp-block-paragraph">Trivy, the widely used security scanner that’s been diligently finding secrets in codebases across the globe, got compromised. A tool designed to spot vulnerabilities became one. If you’re using Trivy, have a small cry about the state of supply chain security.</p><p class="wp-block-paragraph"><a href="https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/">https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/</a></p><p class="wp-block-paragraph"><strong>Being Left Behind Is Actually Fine</strong></p><p class="wp-block-paragraph">Someone wrote a lovely piece about being okay with not keeping up with every new thing. In an industry that breathlessly chases every shiny object, every new framework, every paradigm shift announced via Medium post, there’s something deeply rebellious about saying “no thanks, I’m good here.” We’ve convinced ourselves that standing still is death. Sometimes standing still is just having standards.</p><p class="wp-block-paragraph"><a href="https://shkspr.mobi/blog/2026/03/im-ok-being-left-behind-thanks/">https://shkspr.mobi/blog/2026/03/im-ok-being-left-behind-thanks/</a></p><p class="wp-block-paragraph">In response to the above, <a href="https://www.linkedin.com/in/adrian-sanabria/">Adrian Sanabria</a> <a href="https://infosec.exchange/@sawaba/116273570030885317">went on a rant on Mastodon</a>, which I nodded so much in agreement with I hurt my neck.</p><p class="wp-block-paragraph"><strong>Your Brain Is Leaking</strong></p><p class="wp-block-paragraph">Criminals love it when you’re drowning in notifications, tabs, and unread emails. You miss things. You click things. You approve things you shouldn’t. Digital cleanup isn’t about files anymore. It’s about giving your brain enough space to actually notice when something’s wrong. Marie Kondo would have made an excellent CISO.</p><p class="wp-block-paragraph"><a href="https://blog.knowbe4.com/digital-cleanup-its-not-just-your-files-its-your-brain">https://blog.knowbe4.com/digital-cleanup-its-not-just-your-files-its-your-brain</a></p><p class="wp-block-paragraph"><strong>Trapped By Security Theatre</strong></p><p class="wp-block-paragraph">A cyberattack on a car breathalyser company left court-ordered users unable to start their vehicles. Not because they’d been drinking. Because the servers were down. You’re sober. You’re compliant. Yet you can’t even leave the theatre anymore. You’re just stuck in the car park, breathing into a brick.</p><p class="wp-block-paragraph"><a href="https://www.wired.com/story/security-news-this-week-cyberattack-on-a-car-breathalyzer-firm-leaves-drivers-stuck/">https://www.wired.com/story/security-news-this-week-cyberattack-on-a-car-breathalyzer-firm-leaves-drivers-stuck/</a></p><p class="wp-block-paragraph"><strong>Spite-Driven Insecurity</strong></p><p class="wp-block-paragraph">I left an API key exposed specifically to spite Claude.</p><p class="wp-block-paragraph">Yes, I am petty, I don’t condone it, but my ego is bigger than that. </p><p class="wp-block-paragraph"><a href="https://blog.knowbe4.com/i-didnt-revoke-my-api-keys-because-claude-called-me-an-idiot">https://blog.knowbe4.com/i-didnt-revoke-my-api-keys-because-claude-called-me-an-idiot</a></p><p class="wp-block-paragraph"><strong>AI Ate AI</strong> McKinsey’s AI platform got comprehensively owned by another AI. The attacker found 22 unauthenticated endpoints, exploited SQL injection like it was 2003, accessed millions of messages, and then, just for fun, rewrote the system prompts. Your AI governance strategy is probably a spreadsheet someone created in a panic after a board meeting. This should worry you more than it probably does. <a href="https://blog.knowbe4.com/best-practices-for-implementing-ai-agents">https://blog.knowbe4.com/best-practices-for-implementing-ai-agents</a></p><p class="wp-block-paragraph"><strong>Until Next Week</strong> If any of this made you want to unplug your router and become a bee farmer, you’re having the correct emotional response. If you’ve got stories, rants, or tales of AI betrayal, hit reply. I read them all, usually while my phone is still pretending to have battery.</p><p class="wp-block-paragraph">Stay cynical.</p><p class="wp-block-paragraph"> </p><div class="spu-placeholder" style="display:none"></div><div class="addtoany_share_save_container addtoany_content addtoany_content_bottom"><div class="a2a_kit a2a_kit_size_20 addtoany_list" data-a2a-url="https://securityboulevard.com/2026/03/breach-of-confidence-27-march-2026/" data-a2a-title="Breach of Confidence – 27 March 2026"><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fbreach-of-confidence-27-march-2026%2F&amp;linkname=Breach%20of%20Confidence%20%E2%80%93%2027%20March%202026" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fbreach-of-confidence-27-march-2026%2F&amp;linkname=Breach%20of%20Confidence%20%E2%80%93%2027%20March%202026" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fbreach-of-confidence-27-march-2026%2F&amp;linkname=Breach%20of%20Confidence%20%E2%80%93%2027%20March%202026" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_reddit" href="https://www.addtoany.com/add_to/reddit?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fbreach-of-confidence-27-march-2026%2F&amp;linkname=Breach%20of%20Confidence%20%E2%80%93%2027%20March%202026" title="Reddit" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_email" href="https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Fbreach-of-confidence-27-march-2026%2F&amp;linkname=Breach%20of%20Confidence%20%E2%80%93%2027%20March%202026" title="Email" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share"></a></div></div><p class="syndicated-attribution">*** This is a Security Bloggers Network syndicated blog from <a href="https://javvadmalik.com">Javvad Malik</a> authored by <a href="https://securityboulevard.com/author/0/" title="Read other posts by j4vv4d">j4vv4d</a>. Read the original post at: <a href="https://javvadmalik.com/2026/03/27/breach-of-confidence-27-march-2026/">https://javvadmalik.com/2026/03/27/breach-of-confidence-27-march-2026/</a> </p>