Cybersecurity Reading List - Week of 2026-04-06

Published on: 
April 6, 2026

“The old world is dying, and the new world struggles to be born; now is the time of monsters” - so spoke Italian political theorist Antonio Gramsci nearly one hundred years ago. Or, to be more accurate, around 1930 Gramsci wrote:

La crisi consiste appunto nel fatto che il vecchio muore e il nuovo non può nascere: in questo interregno si verificano i fenomeni morbosi piú svariati.

which has been translated directly as:

The crisis consists precisely in the fact that the old is dying and the new cannot be born; in this interregnum a great variety of morbid symptoms appear.

The vigilance of defenders and investigators often focuses on monsters, typically ones easy to classify and thus easy to articulate wins to management. 

What would our industry look like if instead, we triaged the morbid symptoms of our environments, of our systems? Fighting dragons feels more satisfying than covering fundamentals. How do we frame the problem, get exec on-side, but more importantly, how do we continue to motivate ourselves in a world so seemingly full of morbid symptoms, most outside our control? 

Answers usually don’t survive first contact with reality. For my part, I fall back on a mindfulness of effort. As I plan and execute, my work of 2026 includes asking myself over and over, “Am I chasing monsters, or is there an underlying morbid symptom here that means monsters spawn less, or elsewhere?”

By the way, this is a discussion on impact.

Articles

Image above from Kentik post identifying distinct shutdown phases.

We’ve been busy little gremlins, recently, and our ability at DomainTools Investigations to remain timely and relevant despite being a scrappy little team continues to make me deeply proud. From us over the past month or so:

Research Papers and Reports

Tools and Resources

Related Content

SecuritySnacks
Cybersecurity Reading List - Week of 2026-06-01
Learn More
SecuritySnacks
SecuritySnack - Hijacking Corporate Sessions
DomainTools dissects an AiTM phishing kit targeting Microsoft 365/Entra ID: CAPTCHA cloaking, corporate email harvest, and MFA-bypassing cookie theft.
Learn More
SecuritySnacks
Cybersecurity Reading List - Week of 2026-05-04
Systems thinking, biolistics, and the danger of mop-up science in infosec — plus this month's reading on ransomware, RPKI exploits, cPanel, and LLM pollution.
Learn More