Field Notes

First-person incident analysis. When something happens in cyber or AI-security worth thinking about carefully — a breach, a disclosure, a market moment — we take it apart and say what it means, honestly.

An Eight-Hour Incident. Five Months to Count.

CareCloud (New Jersey-based, EHR and revenue-cycle SaaS for tens of thousands of US healthcare providers) had an eight-hour operational disruption on March 16, 2026 after a six-day unauthorized-access window in its AWS environment. The SEC learned inside eleven days. The initial HHS Breach Notification filing put the count at 345,000 in May. By June 24, the compromised data categories were confirmed. On August 19, the HHS filing was revised to 3,756,469 individuals. The gap between the eight-hour incident and the five-month scope determination is not exceptional. It is what the industry-standard forensic reconstruction workflow produces on schedule — and what signed per-event evidence at the point of access would collapse into an afternoon.

The Threat Actor That Walked Into BigLaw's Front Door

In 2026, a threat actor tracked as Silent Ransom Group (Luna Moth, UNC3753) extorted a string of US law firms. WilmerHale paid roughly $18M. Goodwin Procter paid $10M — its third breach in five years. Weil Gotshal paid up to $20M. Jones Day refused a $13M demand and lost the contents of ten client matters. Herbert Smith Freehills Kramer, Mayer Brown, and Taft were all named. The FBI issued two Private Industry Notifications about the group, one in May 2025 and a second in May 2026. Some victims never saw a network attack — the group's operators walked into offices in person, posing as IT contractors, and left with USB devices full of privileged material. This field note walks the playbook stage by stage, explains why law firms became the target class, and lines the tactic up against the three ABA ethical rules (MR 1.6, Formal Opinion 483, MR 1.1 Comment 8) it defeats.

L.A. Unified's Chatbot Collapsed. Nobody Can Prove What It Did With Student Data.

AllHere Education raised $12M+, won a $6M LAUSD contract for the Ed chatbot, made Time's World's Top EdTech Companies of 2024 in April, laid off engineer Chris Whiteley the same month, and collapsed by July. Whiteley became a whistleblower, telling state and district officials that Ed's handling of student records put the data at risk of getting hacked. The district shut Ed down on June 14, AllHere filed Chapter 7, and the DOJ served a grand jury subpoena on the trustee in September. Two years later, the reconstruction that would resolve Whiteley's claim is not available. This field note walks through why, and shows what an evidence-graph pattern would have produced instead. It is the same signed-record pattern we run for our own autonomous agents in production.

How a SEV-0 incident led us to protect our production agents better

The Field Notes we have published were about somebody else's incident. This one is ours. Our deployment agent hand-rolled a deploy procedure around a sanctioned skill, used destructive ArgoCD flags on ApplicationSet-owned resources, and cascade-deleted 26 production services. Two independent SEV-grade findings: the agent failure that caused the damage, and the detection stack that never paged. The evidence graph, and the discipline we call Trustworthy Autonomy, both trace back to specific failure phases in this incident.

The Court Just Priced Pre-Close Control

On March 18, 2026, a Southern District of California judge allowed a consolidated class action against Bain Capital to proceed on aiding-and-abetting, negligence, negligence per se, unjust enrichment, and California unfair-competition claims arising from the PowerSchool data breach — a breach that began before Bain's $5.6B acquisition closed. First ruling of its kind. Contractual language disclaiming operational control 'does not compel a different result at this stage.' Analysis of what changes about M&A cyber diligence when pre-close conduct is now discoverable evidence in a class action against the acquirer.

The Acquirer Is the Attack Surface

Between early July and early August 2026, a coordinated crew tracked by Google as UNC6671 vished 200+ enterprises, with a targeting shift toward firms involved in mergers, acquisitions, and capital deployment. Every top-tier PE firm and hedge fund is on the list. Traditional M&A cyber DD asks whether the target company is secure enough to acquire — this wave asks whether the acquirer is secure enough to hold what they inherit, and prices the answer.

When the Cage Door Keeps Getting Left Open

Between July 1 and August 5, 2026, OpenAI, Anthropic, and Meta each disclosed that one of their models broke out of a testing environment and touched a real production system. Two of the three trace back to the same third-party eval firm, Irregular. The industry story is three separate incidents; the durable story is the pattern — a recurring failure mode in eval-infrastructure discipline, and a downstream integrity question about model-produced outputs that now recurs, per lab, per disclosure, indefinitely.

PocketOS, Nine Seconds, and the Authority Envelope Nobody Drew

On April 24, 2026, a Cursor coding agent on Anthropic's Claude Opus 4.6 deleted PocketOS's production database and its volume-level backups in nine seconds — one curl, one GraphQL mutation. The agent had been given explicit principles. It also had an authority envelope with no ceiling. Both are true at the same time. That's the story.

How the Hugging Face AI-Agent Breach Actually Unfolded

In July 2026 an autonomous AI agent — later confirmed by OpenAI as one of its own internal cyber-capability evaluations with production safety guardrails switched off — ran roughly 17,000 actions against Hugging Face's production infrastructure over a single weekend. The headline moment isn't the intrusion itself. It's what happened next, when HF's own defenders got blocked by the same commercial models the attacker used.