One Year of Decipher (Relaunched)
It’s been one year since we relaunched Decipher in September 2025. Here are the videos, podcasts, and articles that best reflect our mission statement: Security without fear.

It’s been one year since we relaunched Decipher in September 2025. Here are the videos, podcasts, and articles that best reflect our mission statement: Security without fear.
September 2, 2026 | 4 min read

It’s been one year since we relaunched Decipher in September 2025.
We relaunched the site with the same mission statement we coined when we first launched in 2018: Security without fear.

That mission statement has been more relevant than ever the past 12 months. It has meant three key things: navigating the complex (and sometimes strange) world of cybersecurity with reporting that is grounded in context, relying on trusted voices to understand what’s really happening in the news, and embracing people that maybe aren’t so familiar with terms like Stuxnet or Mustang Panda.
One year later, and looking through our coverage of top news, stories, and video interviews, we’re proud to say that mission statement continues to ring loud and clear.
Here are 10 stories and interviews that defined Decipher’s relaunch over the last year.
The Past is Always Present in Vulnerability Disclosure
The name Nightmare-Eclipse keeps coming up again and again, tied to an actor who became disillusioned with the MSRC disclosure process and began making online threats against Microsoft and eventually publishing a series of six vulnerabilities in Microsoft products. Microsoft’s reaction – a bizarre blog post called “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure” – brought back all kinds of memories from previous strained relationships between Microsoft and the security research community.
Yahoo's Sean Zadig on How to Raise a Hacker Safely and How AI Isn't Changing Everything
Yahoo CISO and Chief Paranoid Sean Zadig returned to the Decipher podcast for a discussion about how to go about getting kids interested in technology and teaching them about hacking (in the broad, classical sense) safely, how rapidly the cybersecurity industry is changing, and what effects AI is and is not having on offense, defense, and the job market.
Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilities
After the OpenAI Hugging Face intrusion, ExploitGym, an evaluation benchmark designed to test if AI agents could use known security flaws to develop working exploits, was thrust into the spotlight. The story behind how ExploitGym came to be is fascinating, and involved multiple collaborations between researchers, students, and private sector companies. We chatted with Zhun Wang and Nico Schiller, two of the central researchers behind and ExploitGym, to learn more.
TeamPCP’s Supply Chain Attack Spree Continues
One of the biggest storylines over the past year has been TeamPCP’s supply chain tear, a self-replicating worm called Shai-Hulud, and a series of attacks that (once again) exposed weaknesses in the open source ecosystem. We talked to Dan Lorenc with Chainguard, Benjamin Read with Wiz, and other industry experts to better understand how TeamPCP works and why the year has marked a turning point for open-source supply chain attacks.
Project Hail Mary is a Hacker Movie. Amaze Amaze Amaze.
The title says it all: Project Hail Mary is a pure hacker movie. If you don’t think so, let Wendy Nather and David Mortman school you on Ryland Grace's hacker ethos and why he and Rocky typify the can-do attitude of hackers everywhere.
Marks and Spencer’s Profit Drop: The Financial Toll of Cyberattacks
In November 2025, British retailer Marks and Spencer revealed further details about the financial hit of a cyberattack earlier in the year that disrupted online sales for months. But the bigger picture is that capturing the full scale of financial hits from cyber incidents is still difficult. Luckily, there are lots of researchers closely tracking data tied to cyber incidents: Ed Bellis with Empirical Security and Wade Baker from The Cyentia Institute walked us through different cost variables behind incidents.
Anthropic’s Claude Mythos is Just the Beginning
We simply can’t make it through this post without talking about AI. Anthropic launched Project Glasswing in April, along with the announcement of Claude Mythos Preview, an unreleased model that Anthropic boasts “can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” We of course had to talk to machine learning expert Gary McGraw and Katie Moussouris, with Luta Security, about their takes on the announcement, which included this gem: “The repo man for technical debt is coming."
The truth about AI model security and what's coming next | Gary McGraw
Speaking of Gary McGraw, we caught up with him a few months later (which feels like years in the AI security news cycle) to chat about some of the more recent OpenAI, Meta, and Anthropic model escapes and discuss what the real risks to enterprises are from agentic AI.
The $285M Drift Protocol Heist Was ‘6 Months in the Making’
Decipher broke down one of the more unique attacks this year: the largest DeFi hack of 2026, which only took attackers 12 minutes to drain millions in user assets – but only after six months of meticulously planned social engineering.
Defeating Online Scams and Disrupting the Cybercrime Chain | Ariana Mirian
Ariana Mirian, co-founder of startup Beesafe, joined Decipher to talk about the mechanics of online romance and finance scams, how the scammers draw in victims over weeks or months, and why user awareness isn't the complete solution to the problem.
Here’s to one year of Decipher (the relaunched version) and many more to come! For further news coverage and analysis, follow us on YouTube, Instagram, and Twitter.
September 2, 2026 | 4 min read