Please enjoy our latest podcast, the weekly Security Sprint, on Spotify, Apple, as well as other locations accessible via the Spotify for Podcasters link or wherever you listen to your favorite podcasts.
This week’s Security Sprint, Dave and Andy covered many topics, including:
Opening
- A Review of the Fiscal Year 2027 Budget Request for DHS — House Homeland Security Committee
- DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels — CyberScoop
- DHS chief signals efforts to reshape CISA — The Record
- CISA and Partners Release Fact Sheet on Securing Automatic Tank Gauge Systems
- Industry Collaboration and Resilience is a Team Sport — Cyber Threat Alliance — 02 Jun 2026. This article is authored by the Executive Director of IT-ISAC and emphasizes the importance of collaboration across industry, government, and nonprofit organizations to improve cyber resilience.
Main Topics
Safeguarding OUR SECRETS — IC3 — 03 Jun 2026. Five Eyes agencies warned that Chinese military intelligence services are using Western online job platforms and professional networking sites to recruit people with access to classified, privileged, or sensitive information. The alert describes recruiters posing as consultants, think tanks, human resources firms, or fake companies and using trial reports, encrypted messaging, and payments including cryptocurrency to obtain non-public information. The risk extends beyond cleared personnel to military members, academics, journalists, policy analysts, think tank staff, and others with indirect access to sensitive government or defense information. Target is security clearance holders, defense personnel, government contractors, researchers, and corporate security teams with Dig highlighting foreign intelligence recruitment through online job platforms and freelance work channels.
- Applicant Beware – Who Is Recruiting You? — NPSA — 03 Jun 2026
“Patch Now!” Most organizations that miss 24-hour patch window report breaches. Gate 15 note: We’ve been discussing this a lot in recent exercises and meetings. The time to safely address Known Exploited Vulnerabilities is limited and decreasing. Attackers’ speed is accelerating; exploited vulnerabilities are a major point of attack. Article via DataBreaches.net — 02 Jun 2026. The report highlights findings that organizations missing rapid patching windows are more likely to report breaches. The item underscores how quickly attackers weaponize newly disclosed vulnerabilities and how delayed remediation can translate into real incident exposure. The operational lesson is that vulnerability management must account for exploit speed, asset criticality, exposure, and compensating controls rather than relying only on routine patch cycles. Target is vulnerability managers, CISOs, IT operations teams, and executive risk leaders with Dig highlighting the breach risk created by slow remediation of high-priority vulnerabilities. CISA KEV & Other Threat Updates:
AI! Promoting Advanced Artificial Intelligence Innovation and Security — The White House — 02 Jun 2026
- Opinion from Jen Easterly: The Government Is Finally Taking A.I. Risk Seriously
- Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator — Anthropic
- What we learned mapping a year’s worth of AI-enabled cyber threats — Anthropic
Quick Hits
- Ransomware Group Claims Cyberattack on Buffalo Convention Center — Skift Meetings — 01 Jun 2026. Skift Meetings reports that the Akira ransomware group claimed it stole 46 gigabytes of data from the Buffalo Convention Center, including employee records, contracts, financial information, and personal data tied to approximately 180,000 individuals. “Ben Taylor, resilience director at Gate 15, cautioned that ransomware groups often exaggerate the scope of stolen data. The reported figure of 180,000 affected individuals could reflect information obtained through a third-party vendor, a direct breach of venue systems, or inflated claims intended to increase pressure on victims… Taylor recommends planners ask venues about cybersecurity oversight, recent risk assessments, cyber insurance coverage, breach notification protocols, and what type of attendee or exhibitor data can be affected if an incident occurs. He also recommends checking if a venue carries cyber liability insurance, and for how much? ‘Obviously, this type of thing is not one size fits all, and the size of the organization, the sensitive nature of the business, or attendees, will all impact how much risk a planner may be willing to take on,’ said Taylor.”
- Knicks Watch Party at Garden Is Canceled, as Game 3 Security Ramps Up — The New York Times
- FIFA World Cup 2026 Scams Are Already Here: Fake Tickets, Phishing Sites, and Crypto Cons Exposed
- Hackers are hoping to score at the World Cup
- At least 12 wounded near Ohio festival as police hunt multiple gunmen
- Hurricane Season!
- Software supply chain attacks: check your dependencies — NCSC


Read more about Gate 15’s full podcast menu at our Podcast page. You can subscribe and enjoy all the Gate 15 Podcasts on Spotify for Podcasters, Apple, Spotify, as well as other locations accessible from the Spotify for Podcasters link. Week-to-week, you can hear and learn more about our all-hazards threats, risks, mitigation and other issues impacting homeland security risk management from our team as well as our regular and special guests. The full podcast menu includes:
- The Security Sprint is our weekly rundown of the week’s notable all-hazards security news, risks and threats and some of the key focus areas for organizations to consider behind the headlines. Gate 15 team members discuss physical security, cybersecurity, natural hazards, health threats and other issues across our environment.
- Nerd Out! Security Panel Discussion, moderated by Dave Pounder, focuses on physical security topics including terrorism, extremism, hostile events, and other pertinent topics.
- The Gate 15 Interview, is a monthly interview between Gate 15’s founder and Managing Director, Andy Jabbour and guests from throughout the homeland security risk management community addressing a wide range of all-hazards topics and issues.
- The Cybersecurity Evangelist, with Jennifer Lyn Walker, is a cybersecurity-focused discussion with Jen and invited guests. This is presently a Gate 15 special podcast and occasionally is updated on our Gate 15 podcast channel.
- Venue Security, The IAVM Podcast Series was a 2024 limited series podcast as Gate 15’s founder and Managing Director, Andy Jabbour hosted a series of short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
- The Risk Roundtable, was a monthly discussion among our team and occasional guests exploring the all-hazards threats and risks impacting the United States and internationally. This was suspended in September 2023.
We hope you’ll subscribe, listen and share your ideas and other feedback! Reach out to us on Bluesky, LinkedIn, via email at Gate15@gate15.global.
