Please turn JavaScript on
The Nine Lives Brief banner
The Nine Lives Brief icon

The Nine Lives Brief

Subscribe to Nine Lives, Zero Trust, and get security insights delivered to your inbox.

Here's what you'll get:

  • Zero Trust insights you can actually use

  • DevSecOps practices for building security into your pipeline

  • Threat intel worth knowing

  • Cloud security tips from the trenches

  • Secure coding and shift-left strategies

  • The occasional cat pun (we're paranoid about spam, not fun)

Whether you're building secure infrastructure, automating compliance, or navigating the multi-cloud maze, this newsletter has you covered.

Filter by topic to get precisely what you need. Unsubscribe anytime.

Stay curious. Stay secure. Land on your feet.

Message History

Microsoft is changing three parts of the Entra authentication and recovery experience between now and next March:

On September 1, 2026, users enabled for SMS or voice begin moving into Microsoft-managed passkey registration. Microsoft says SSPR will accept only explicitly registered authentication methods, but its published campaign and ...

Read full story

Microsoft published its technical analysis of GigaWiper on July 9, 2026. Microsoft describes it as a modular backdoor with destructive capabilities, including scheduled-task persistence, RabbitMQ-over-AMQP command C2, Redis status and output reporting, potential file transfer to remote storage through the MinIO client, interactive system management, event-log...


Read full story

CISA revised the Microsoft Expanded Cloud Logs Implementation Playbook on May 1, 2026. The document itself is not a shiny new product launch. The revision history calls it version 1.1 with general content and URL up...


Read full story

Prompt injection is easy to underestimate when the model can only answer with text. The worst outcome looks like a bad summary, a leaked instruction, or a response that followed the wrong source.

In a tool-using agent, that assumption breaks fast.

A compromised document, support ticket, website, email, or retrieved chunk can influence the model’s next tool call....


Read full story

A Linux local privilege escalation bug is easy to dismiss if you only think in traditional server terms: “An attacker already needs local access, so how bad can it be?”

In cloud environments, that assumption breaks fast.

A compromised container, a self-hosted CI runner, a developer box, a notebook environment, or a low-privileged shell on a Linux workload can al...


Read full story