CyberDesserts
Learn Cybersecurity By Doing

Latest

16
Apr
Dark code editor displaying JavaScript import statements, representing the npm dependency ecosystem that supply chain attacks target

How Attackers Target npm Maintainer Accounts

April 2026 The registry trusts credentials, not identity. Detection time for npm maintainer account attacks has compressed from months to
19 min read
14
Apr
A glasswing butterfly resting on a green leaf, its transparent wings revealing the leaf surface beneath

Claude Mythos Preview: Project Glasswing Solves One Problem. Here Are the Other Two

April 2026 On 7 April 2026, Anthropic announced that Claude Mythos Preview had autonomously found thousands of zero-day vulnerabilities across
4 min read
08
Apr
Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

April 2026 Scattered Spider is a financially motivated cybercrime collective responsible for some of the most disruptive attacks in recent
17 min read
07
Apr
Developer desk with a "No Bad Days" sign, keyboard, coffee mug and monitor taken before the axios npm supply chain attack made March 31 2026 a very bad day

Axios NPM Supply Chain Attack (2026): What Happened and What to Do

On March 31, 2026, two malicious versions of the axios npm package were published using a compromised maintainer account. The
8 min read
05
Apr
Chess piece knocking over a king on a chessboard, representing strategic decision-making in cybersecurity risk management.

Information Security Metrics for Executives: How to Close the Value Gap

April 2026 The gap between how security teams measure their work and how boards evaluate organisational risk is not a
6 min read
04
Apr
Laptop displaying code in a dark environment with blue and pink lighting, illustrating the developer tooling decisions at the centre of Anthropic's OpenClaw subscription change.

Anthropic Cuts OpenClaw Off Claude Subscriptions And It's Just the Start

Last updated: 5 April 2026 | What's changed: Initial publication covering April 4 enforcement. Get updates like this delivered
3 min read
02
Apr
2026 DevSecOps lifecycle blueprint showing Code, Build, Test, Release, and Deploy. Features Git, Kubernetes, Terraform, and Policy-as-Code. Displays +38% vacancy growth and $2.4M impact stats

Cybersecurity Career Report: April 2026

CyberDesserts | blog.cyberdesserts.com | April 2026 The cybersecurity skills shortage in 2026 is not a headcount problem. It is a
25 min read
31
Mar
A ginger cat viewed from behind, sitting in front of a blurred monitor displaying code

What Censys's OpenClaw Count Reveals That February's Headlines Did Not

31st March 2026 OpenClaw's internet-facing exposure has fallen sharply since the February 2026 peak. Public scrutiny, repeated security
9 min read
30
Mar
Person browsing books on a library shelf

Best Cybersecurity Books for 2026

March 2026 Most cybersecurity book lists are generic. This one is different. Every recommendation here is either used in practice
20 min read
27
Mar
Your Father Spent His Life Savings on Claude Code and We Shipped Nothing

Your Father Spent His Life Savings on Claude Code and We Shipped Nothing

March 2026 On AI slop, borrowed thinking, and the skills that matter when everyone has the same tools. The meme
5 min read