🏠 HOME
💸 MONEY
🎯 SUCCESS
🧠 Brain 🌍 Travel Archive 🚀 Space Archive 🎙️ Podcasts 📺 Video Archive 🎥 Crime & Movies
  • Skip to main content

Mad Mad News

LIVE ABOVE THE MADNESS

Order Now • Check Delivery Today
As an Amazon Associate I earn from qualifying purchases. Delivery availability varies by item and location.

SUCCESS


As Bitcoin Rallies, These 3 Factors Will Determine Crypto’s Comeback

August 25, 2026 MMN Editor Filed Under: Uncategorized

Crypto investors are finally getting some welcome news: Bitcoin has surged above $70,000 for the first time in more than two months — a sharp rebound after spending much of the summer stuck in the $60,000 range.
Now, bitcoin is inching towards $80,000. But even after this rally, it remains roughly 10% below where it started 2026. The roughly $125,000 record it reached last fall is a distant memory. And it’s been an even tougher year for other popular cryptocurrencies, like ether and cardano.

Must Read

10 Smart Ways Seniors Are Earning Extra Money
Your Social Security Number Isn’t ‘Suspended’ — That Phone Call Is Probably a Scam
Silver Is Up 70% Since This Time Last Year — and These Gold IRA Companies are Handing Out Up to $25,000 of It

The slump might seem surprising. After all, crypto is easier than ever to buy, and regulators have become friendlier to the industry. Major financial companies are offering a growing number of ways for people to use and invest in digital assets.
So why haven’t prices followed? Vanessa Grellet, managing partner at crypto venture firm Arche Capital, says last fall’s selloff did lasting damage.
“Every time [borrowed money] comes out of the crypto markets, there’s a huge crunch,” she says. Combined with concern over tariffs and interest rates staying higher for longer, that has made it especially difficult for crypto to recover.
Whether these conditions change — and the price of crypto ends the year on an upswing — will depend on how it squares up to several challenges in the coming months.
1. Can crypto win back investors?
Crypto needs buyers, and for much of this year, demand has been lacking.
On Robinhood, for example, crypto trades through the app totaled $18 billion during the second quarter, down 35% from the same period last year. That wasn’t because Robinhood users stopped trading: Stock trading volume on the platform jumped 85% from a year earlier, while options activity increased 50%.
Activity elsewhere in the market has been unusually dull, too. Luke Deans, a senior research associate at crypto asset manager Bitwise, told CoinDesk earlier this month that traders were becoming accustomed to bitcoin’s quiet trading cycle to the point that they expect “very little will happen.”
Professional investors haven’t exactly been piling in, either. U.S. spot bitcoin ETFs (exchange-traded funds) recorded $4.9 billion in net withdrawals during the second quarter, according to the New York Digital Investment Group. Those funds have become one of the most important avenues for new money to enter the market since their debut in 2024.
Crypto also faces more competition, with artificial intelligence gradually replacing digital currencies as the buzziest speculative asset.
Grellet says that shift has been significant. “All the attention got crowded out to AI” earlier this year, she adds, explaining that “we see talent and money moving out of crypto and into AI because of the proximity between the two.”
Basically, traders as well as developers seem to think crypto feels boring and have adjusted accordingly. But this week’s rally shows how quickly that sentiment can change. The bigger test will be whether investors keep buying after the initial excitement fades.
For ordinary investors, one indicator to watch is money flowing into bitcoin ETFs. Sustained investment into these funds would suggest traditional investors are becoming more willing to take a chance on crypto again, while continued withdrawals could signal that enthusiasm remains low.

Must Read

Retirees Are Doing These 10 Things to Add to Their Monthly Income
Your Social Security Number Isn’t ‘Suspended’ — That Phone Call Is Probably a Scam
Warren Buffett on Market Volatility — and 3 Ways You Can Take Advantage

2. Will the Fed hike interest rates?
Although the Federal Reserve held its benchmark interest rate at 3.5% to 3.75% in July, three officials voted to raise rates by another quarter percentage point.
This matters because when interest rates are high, investors can earn meaningful returns from traditionally safer investments such as Treasury securities and savings products. That can make taking a chance on an asset such as bitcoin less attractive. Lower rates can have the opposite effect by encouraging investors to seek higher returns elsewhere.
Bitcoin’s recent rally offers an example of how sensitive crypto remains to those conditions. The cryptocurrency’s value jumped after the Treasury Department increased purchases of long-term government bonds, pushing yields lower. Optimism about crypto legislation may also have contributed to the move.
That doesn’t mean lower rates guarantee higher bitcoin prices. Chris Kuiper, vice president of research at Fidelity Digital Assets, noted in an August report that bitcoin hasn’t been responding to increases in global liquidity the way it historically has.
Nonetheless, Fed policy, inflation and bond yields will remain important clues about how willing investors may be to take risks through the end of the year.
3. Can mainstream finance embrace it?
Despite crypto’s difficult year so far, the industry itself remains firm. For one, stablecoins — digital tokens generally designed to remain worth $1 — still represent a market of roughly $300 billion. Tether alone accounts for more than $180 billion.
The appeal of stablecoins might be difficult to understand for many Americans. Bank accounts, credit cards and payment apps already make dollars easy to store and move.
But for Austin Campbell, founder of advisory firm Zero Knowledge Consulting, the picture looks different elsewhere in the world. He says Americans tend to take plentiful access to dollars and a functioning financial system for granted, but “if you live in Turkey or Nigeria or Venezuela, suddenly being able to have that is life-changing.”
Traditional financial companies are also continuing to move deeper into digital assets.
In April, Franklin Templeton announced plans to acquire crypto investment firm 250 Digital. Chris Perkins, one of the firm’s executives, told The Wall Street Journal that institutional attitudes have shifted substantially. Whereas firms once worried about the reputational risk of entering crypto, he said, institutions now face “reputational risk for not being in the space.”
But 2026 has also demonstrated an important distinction: A growing crypto industry does not automatically mean rising crypto prices.
Grellet says that disconnect between stronger institutional support and sluggish prices may just be a timing issue. Major banks and brokerages like Bank of America, JPMorgan and Charles Schwab have announced more crypto products, but many are still building the systems and infrastructure needed to offer them to a wider audience.
“It’s just a delayed reaction of the markets,” she says. “Traditional finance takes time and needs to do things right.”

Alibaba makes another bold move after $10.2 billion AI funding deal

August 25, 2026 MMN Editor Filed Under: Uncategorized

Michael Burry sold his Alibaba position and vowed not to buy it back unless shares fall 50% from current levels. One day later, Alibaba’s CEO put $15.3 million of their own money into the stock, Seeking Alpha reported.

That is the entire Alibaba story in two sentences. And figuring out which side to be on is one of the more interesting debates in AI right now.

On Sunday, Aug. 23, Alibaba announced it would raise HK$80 billion. That’s approximately $10.2 billion, through a Hong Kong share placement to fund its artificial intelligence buildout. 

The offering is Hong Kong’s largest-ever follow-on offering. By the next day, Aug. 24, the Hong Kong-listed shares had fallen 8.5%, with an intraday decline of up to 10%. U.S. ADRs dipped to around $118. 

The offering was priced at an 8.4% discount to the prior closing price, creating dilution, according to TheStreet.

Chairman Joseph Tsai purchased 720,000 shares at an average of $14.29, worth approximately $10.3 million. CEO Eddie Wu bought 350,000 shares at $14.24, valued at roughly $5 million. 

Burry left the Alibaba position: why his timing worked perfectly

I have covered Burry’s Alibaba moves multiple times. My colleague at TheStreet continues to note that his relationship with the stock has been a series of reversals.

Burry built it into his largest holding in 2024, liquidated the whole position in Q1 2025, reversed again in April with a new stake, and then switched the entire Alibaba position into JD.com.

“Issuing shares is now its new paradigm,” Burry wrote on X (formerly Twitter), giving his reason for the final exit. He said Alibaba shares would need to fall roughly 50% before he would consider buying again.

The timing worked in his favor almost immediately this time. Alibaba confirmed the $10.2 billion placement within weeks of Burry’s exit, and the 8.5% single-day decline validated his dilution concern in real time. 

This is actually not the first time Burry’s exits have looked prescient in hindsight. The man reads balance-sheet shifts faster than most.

Related: After Burry ditched Alibaba for JD, Alibaba proved his point

His core concern is that the AI buildout fundamentally transforms what Alibaba is.

It was a capital-light e-commerce marketplace printing extraordinary returns. It is becoming an AI infrastructure company that requires heavy capital for each incremental dollar of revenue.

BABA’s AI infrastructure offers a small percentage of pre-tax return after operating expenses, Reuters reports. At the same time, free cash flow is turning negative, and capital expenditure expectations are doubling by fiscal 2029.

The business case that Alibaba’s Tsai and Wu are betting on

Here is something a little complicated, because the underlying Alibaba business is not weak.

Revenue for the quarter ended June 30, 2026, was approximately $39.6 billion, up 9% year over year, according to the company’s quarterly results. 

Cloud revenue growth accelerated to 45%. AI-related product revenue delivered triple-digit growth for the twelfth consecutive quarter. Cloud adjusted EBITDA margin reached 12%, improving from the prior year.

Related: Alibaba’s $10.2 billion AI bet could reach far beyond investors

“Alibaba Cloud’s external revenue growth accelerated to 45%, with AI-related product revenue delivering triple-digit growth for the twelfth consecutive quarter,” said CEO Eddie Wu in the quarterly release. 

CFO Toby Xu added that “AI monetization ramps up” and the company has “greater strategic and financial flexibility to make disciplined and sustained investments.”

I think this is the bull case Tsai and Wu are personally backing with $15.3 million. Twelve consecutive quarters of triple-digit AI revenue growth are not just a narrative. Or luck.

It is a track record. But there’s a problem. The question now is whether the capital required to sustain it destroys the shareholder return profile faster than the revenue growth creates value.

Alibaba Chairman Joseph Tsai purchased 720,000 shares at an average of $14.29, worth approximately $10.3 million. CEO Eddie Wu bought 350,000 shares at $14.24, valued at roughly $5 million. Future Publishing via Getty Images

The investment thesis collision: Who’s right?

My honest answer is that both Burry and Tsai can have defensible positions simultaneously.

Burry is right that the offering creates real dilution and signals a business-model shift away from the buyback-driven shareholder return thesis that made Alibaba attractive in 2024 and 2025. The dilution from a single capital raise is not trivial.

More Manager Buy/Sells:

Michael Burry increases his bet against the popular chip giant

Warren Buffett reveals he broke his own investing pattern

Mark Cuban bets on MLB with Athletics minority stake

Tsai and Wu are right that Alibaba is executing at the center of China’s AI infrastructure buildout with accelerating cloud revenue, improving margins, and a product portfolio that is generating real commercial demand.

The third point worth noting is that the $10.2 billion offering ranks third-largest globally this year, behind only Alphabet and Intel, according to a BigGo Finance report. When Alibaba needs to raise capital at that scale, it signals that the AI infrastructure race is capital-intensive everywhere, not just in the U.S.

BABA is down 18.87% year to date and 2.75% over the past year, according to Yahoo Finance. BABA has been a frustrating hold through a year of AI enthusiasm that rewarded U.S. semiconductors and infrastructure names while leaving Chinese tech underperforming.

Also Read: History of Alibaba: Timeline and Facts

You’re probably wondering whether the chairman and CEO buying $15.3 million in the same week Burry exits marks a bottom. They could be defending their own stock narrative as insiders. Maybe they see something the market doesn’t. Or maybe it means nothing at all. That’s the question we are all sitting with now.

The 5-year return of -26.68% makes it clear that Alibaba’s promise has outrun its delivery more than once. Now, I think this AI buildout is either the chapter where that changes or just the next version of the same story.

Related: Michael Burry says Nvidia rival is quietly getting serious 

Dolly Parton, Legendary Singer And Actress, Dies At 80

August 25, 2026 MMN Editor Filed Under: Uncategorized

Dolly Parton, the iconic singer, songwriter and philathropist who recorded such tiumeless hits as “Jolene” and starred in the classic movie comedy “9 to 5,” has died.

‘Reacher’ Season 4, Episode 5 Release Time: Here’s When This Week’s Episode Drops On Prime Video

August 25, 2026 MMN Editor Filed Under: Uncategorized

Here’s when Reacher Season 4, Episode 5 “Bridge” comes out on Prime Video, including the August 26 release date, streaming time and full schedule.

Here’s where it takes new homeowners almost 40 to 50 years to break even on buying a house

August 25, 2026 MMN Editor Filed Under: Uncategorized

In some markets, renting and investing can build wealth faster than buying a house.

Chevron stock turns heads as company strikes fresh oil

August 25, 2026 MMN Editor Filed Under: Uncategorized

Chevron (CVX) confirmed a fresh oil find off the coast of Angola on Aug. 17. 

Within days, the stock neared its all-time high.

The timing was especially important for the company. 

Chevron is already posting record profits and paying a growing dividend, and this discovery gives shareholders one more reason to think both can keep climbing. It also tells you something about how Wall Street sees the company right now. 

Here is what Chevron found, why it matters for investors’ dividends, and where the risks still sit.

What Chevron actually found off the coast of Angola

Chevron has confirmed a new oil and gas condensate discovery at its 105-4X well in Block 0, offshore Angola.

The well sits in the Lower Congo Basin, a stretch of ocean where Chevron has been pumping oil for decades. That makes it familiar ground, not a gamble on some untested frontier.

Related: Scott Bessent sends strong message on oil price and Iran

The results were good. The well hit an oil and gas condensate column stretching more than 600 meters, about 2,000 feet, in the main Pinda reservoir.

Within that column, the company logged over 90 meters, roughly 300 feet, of what it called excellent-quality net pay. 

Net pay is simply the slice of rock that can actually produce oil, so a thick, clean section like this one is a promising sign.

Why the market pushed Chevron stock toward a record

Chevron closed at $205.27 on Aug.21, a few dollars away from its record and up about 35% for the year, TIKR reported.

Most of that climb has come from oil prices, which increased as tensions around the Strait of Hormuz raised fears about global supply.

One well, on its own, does not usually move a company this size. 

Chevron is worth about $405 billion, Robinhood data shows, so a single discovery is a small piece of the whole.

What excites the market is the message behind it. 

Chevron just showed it can still find cheap barrels in places it already understands, instead of pouring money into risky new regions. For income investors, that kind of quiet, low-cost growth is exactly what they like to see.

Chevron used the jackup rig Shelf Drilling Tenacious to drill its 105-4X well offshore Angola.Cheng Xin / Getty Images

How the discovery reaches your dividend faster

Instead of building an expensive new platform, Chevron wants to tie the discovery back to facilities it already runs nearby.

A tie-back links a new well to existing infrastructure through undersea pipelines. It reduces both the cost and the wait, so the oil reaches the market sooner and at a better margin.

More Energy Stocks:

Scott Bessent’s Hormuz declaration puts Chevron at the center

BofA just turned on Exxon in favor of Chevron

The Red Sea just got more dangerous for Saudi oil

More margin means more cash, and cash is what keeps the dividend flowing.

In July, Chevron’s board declared a quarterly dividend of $1.78 per share, payable Sept. 10, confirmed in a press release. 

That adds up to $7.12 a year, a yield of about 3.5% at today’s price. To put that in real terms, someone holding 500 shares collects roughly $3,560 a year in dividends, before the stock moves a dime.

The earnings power behind the payout

Chevron earned an adjusted $6.06 per share in the second quarter of 2026, topping Wall Street’s estimate by about $0.50, Chevron reported.

Total revenue landed at $70.06 billion, beating Wall Street’s forecast of about $62.26 billion by more than 12%, Investing.com reported. 

The company also threw off $15.4 billion in free cash flow.

Free cash flow is what is left after the bills are paid and projects are funded, and it is the pot the dividend comes out of.

With that money, Chevron paid down $8.4 billion in debt and bought back $3 billion of its own shares in a single quarter.

Analysts expect full-year adjusted earnings to roughly double to about $15.72 per share in 2026, which more than covers the $7.12 dividend, the Motley Fool reported.

Where Wall Street sees Chevron stock going next

Most analysts read the Angola find as proof that Chevron can grow without overspending.

On Aug. 19, Morgan Stanley lifted its Chevron target to $218 from $210 and kept an Overweight rating. That is above the stock’s record high near $215.

The average target across 17 Wall Street analysts is $216.50, above where the stock recently closed.

Not everyone is bullish, though. Two days before Morgan Stanley’s move, Barclays reduced its target to $208, a hint that the shares may already be trading close to fair value.

What this discovery does not fix

A good oil discovery is worth celebrating, but it does not erase Chevron’s biggest risk.

The stock still depends completely on the price of crude. Much of this year’s rally traces back to the oil spike tied to Middle East supply fears, not to any project.

3 things to watch as a Chevron shareholder

Crude prices: If tensions cool and Brent drifts back toward the low $80s, Chevron’s earnings and its stock could give back ground.

Timeline: The tie-back is still under review. Chevron has not said how much oil the well can produce or when it will start flowing.

Valuation: With the stock near record highs and analyst targets close by, a lot of good news may already be priced in.

The oil find makes the long-term outlook stronger, but it will not protect the stock if oil slips over the next few quarters.

The bottom line for Chevron investors

Chevron’s Angola oil discovery is a genuine win. It adds cheap barrels in a region the company knows well, and the tie-back plan means those barrels can reach buyers quickly and at low cost.

Add that to record profits, shrinking debt, and a dividend that looks well protected, and it is easy to see why investors keep holding on.

The one thing to watch is the price you pay. 

Chevron sits near record highs, analyst targets are within reach, and the stock is still tied to a crude market that has already handed investors most of this year’s gains.

If you are holding for the long haul and the dividend, this discovery only strengthens your case. 

If you are buying today, remember that where the stock goes next depends far more on the price of oil than just a single well off the coast of Angola.

Related: BofA commodities expert reveals what must happen before oil prices fall

This driverless-truck company could be a ‘long-term winner’ in a market Tesla plans to enter soon

August 25, 2026 MMN Editor Filed Under: Uncategorized

Kodiak AI logged more than 40,000 paid driverless hours through the second quarter and is pushing to offer driverless highway operations by the end of 2026.

How to Turn Your Career Story Into a Magnet for Opportunity

August 25, 2026 MMN Editor Filed Under: Uncategorized

Since the dawn of time, storytelling has been central to human culture. Our ability to transform experiences and explain the world around us through a story is one of our greatest assets. In a world increasingly shaped by AI, human stories will become a staple in every aspect of our lives. In our personal relationships, on social media, and in our careers.
Speaking of careers, presentation specialist Nancy Duarte writes, “Today, stories are becoming more pervasive in business because they make ideas, data, and plans relatable, recallable, and repeatable by associating information with powerful feelings.”
Resumes that read like long lists of accomplishments might look impressive, but readers get tired of them relatively quickly. This doesn’t mean numbers are unimportant. It just means incorporating them into a story is how you’ll make a lasting impression.
Why a career “story” beats a career “history”
Outlining your work history is the classic approach, and classic is perfectly fine. It can, however, lean a bit predictable. Whereas a career history is looking backward at your achievements (“here’s what I did”), a career story is looking forward (“here’s where I’m headed and why that matters”)
When you make your trajectory obvious, opportunities tend to flow toward you naturally. Why? Because visionary companies would rather invest in momentum than a plain list of duties. Thousands of candidates will list the software they worked with. Articulating the deeper purpose behind your work and the specific problems you want to resolve next will actually set you apart.
The 3 ingredients of a magnetic career story
Creating a magnetic career story takes some preparation. Here’s what you need to do:

Figure out the one thing that connects all your roles. A career history will focus on your titles, whereas a career story will find a consistent thread in the problems you solve, the support you provide or the creative approach you apply to every challenge.
Give evidence of impact. Numbers and quantified achievements can serve as the hook to your story, as they’re easily spotted on a resume. Hiring managers want to see results and actual proof of how good you are at what you do. But telling the story of how you came up with a marketing idea that led to 20% increase in sales is what will really stick in readers’ minds.
Provide a clear direction. To turn your career history into a career story, keep your eyes on the future. Show that it excites you and you have a clear vision for where you’re headed and what you’re hoping will happen when you get there. This will give both you and your potential employer confidence in your abilities.

How to excavate your story (even if you think you don’t have one)
You might be thinking, “Well, I don’t really have a story to tell,” but that’s highly unlikely. Everyone has a story. Think about the problems people keep coming to you for. What are you proud of that isn’t on your resume yet? Where did you create measurable change?
Mine both failures and successes. It’s easy to tell the story of a win, but the real mastery is showing how a loss helped you reinvent yourself and your work. Everybody makes mistakes at their jobs, and the cliché is true: that’s how you really grow.
We’re not suggesting you state your failure outright and give no context. Try to distill what you learned and show the outcome of that lesson.
Translating your story onto the page
Your career story should be visible in the places where opportunity actively looks. Networking and sharing on social media are essential, but what if the LinkedIn post you poured your heart into never reaches your dream employer?
The reality is that your resume is still the anchor document. It is the foundational text that feeds your LinkedIn profile, directs your portfolio structure, and populates recruiter searches across applicant tracking systems (ATS).
Translating your experience is the real challenge. How do you take a rich, dynamic internal narrative—your purpose, your momentum, and your visionary goals—and condense it into a document that is optimized for both the ATS and the human?
The trap most professionals fall into is stripping away the story to satisfy the algorithm, but humans are still the ones who read your resume in the end. You don’t want to accidentally flatten your vibrant career arc into a robotic chore list.
The best resume builders to bring your story to life
Fortunately, you don’t have to figure out how to do this on your own. To help yourself in the process, trust a modern resume builder. The right tool will help you edit your document, tailor your bullets, and format your experience in a way that feels cohesive and part of an exciting story.
Here are some of the most effective builders on the market today and what they’re best for:

Enhancv (Best for crafting a career story). Instead of forcing you into standard duty-driven layouts, Enhancv’s AI Resume Builder uses content-guided sections and tailored suggestions. The built-in AI assistant helps translate mundane tasks into strong, results-oriented accomplishments. The result? A standout, modern resume that captures your unique trajectory while remaining completely ATS-friendly.
Teal (Best for targeted applications). Teal excels at job-description matching and tracking your applications. It allows you to tweak your story with no fuss and add the right keywords to perfectly match each job posting.
Canva (Best for total creative control). Canva is considered the top choice when it comes to design. It provides the blank canvas needed to construct a striking, highly customized aesthetic. However, users should keep in mind some of the designs aren’t ATS-compatible and aim for a relatively simple layout.
Resume.io (Best for speed and corporate polish). Resume.io offers sleek, minimalist templates that quickly organize your career timeline into a scannable format. It is a highly reliable choice when you need a clean, conventional document generated in minutes.

Where your story should live (beyond the resume)
Your resume is the main event in your job application package, but that doesn’t mean you shouldn’t maximize your influence as much as possible. Cover the entire job-hunting ecosystem, starting with LinkedIn. Use your headline to state your current job title as well as the title you’re striving toward. Your “About” section is the perfect spot for real, human storytelling instead of stiff corporate jargon.
If you’re comfortable with social media presence, use it to your advantage. If not, a simple personal website or a digital portfolio acts as your professional headquarters, giving you the opportunity to tell your story on your own terms and in your preferred format.
Finally, communication really is key, especially on a daily interaction level. When you introduce yourself at a networking event or reach out to a founder in a DM, lead with your vision.
Conclusion
For too long, professionals have been taught to list their past duties and wait for the employer to make a story out of them.
You are the captain of your ship. Show you’re armed with a unique and clear vision for the future and that you’re confident in where you’re going. Translate your story into a powerful resume, and then project it across your entire digital ecosystem. That’s how you stop chasing the market—and let the market come to you.
The post How to Turn Your Career Story Into a Magnet for Opportunity appeared first on Addicted 2 Success.

Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.

August 25, 2026 MMN Editor Filed Under: Uncategorized

A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong. Prompt injection has held the No. 1 spot on the OWASP Top 10 for LLM Applications for three consecutive years. When two leaders of that list checked it against 6,639 labeled real-world incidents, it came back at No. 12. The drop measures visibility rather than danger, because the attack operates where a vulnerability scanner cannot see it.That finding belongs to Kyriakos “Rock” Lambros and Steve Wilson, two leaders of the OWASP Top 10 for LLM Applications project, who published it on arXiv on August 18 with the disclaimer attached. The analysis is exploratory, not peer reviewed, and not the official OWASP release, and the authors state it does not supersede the official list or its process.The machinery behind it is real: 7,714 LLM security incidents from CVE, GitHub Security Advisories, OSV, and the AIAAIC AI-harm database, 6,639 of them labeled against a 20-entry taxonomy, and a Bayesian model that corrects each count for classifier error before setting the data-driven ranking beside the expert vote.The comparison found no statistically detectable agreement between expert judgment and the public incident record. Cohen’s kappa comes in at 0.20 with a 90% interval running from negative 0.16 to 0.57. “The interval crosses zero, so we cannot rule out that the two rankings agree only by chance,” they write. “The honest bottom line: weak agreement, not confirmation.”Lambros, co-lead of the OWASP GenAI Security Project Top 10 for LLM Applications and director of AI standards and governance at Zenity, put the finding in evidentiary terms in written answers to VentureBeat. “We had two ways of measuring the same risk, expert judgment and the public incident record, and they disagree with each other. Neither one is the truth,” Lambros said. “Two witnesses are contradicting each other, and we can’t tell you which one is lying.”The attack chain a scanner never logs The gap is structural. Prompt injection hides instructions inside the content a model reads, anything from a log entry to a support ticket to a document pulled back by retrieval. The agent then makes the tool call the attacker wanted, using credentials it legitimately holds. Nothing in that chain is a product defect, so the attack leaves no CVE behind for a scanner to find.The defenses that catch it are adversarial tests against the deployed system and hard caps on what the agent can reach, so a fooled model cannot touch anything expensive. The same logic argues for funding agent memory and MCP tool boundaries now, on architecture, rather than waiting for advisory volume that will always arrive a cycle late.The first control Wilson would deploy Wilson, Chief AI and Product Officer at Exabeam and project co-lead for the OWASP Top 10 for LLM Applications, named the control he would deploy first against exactly that chain, an agent that reads an attacker’s payload in a log file, treats it as an instruction, and rewrites DNS with a valid credential, in written responses to VentureBeat.“The first thing I’d do is put an authorization gate outside the model: the agent can propose the exact DNS change, but it cannot grant itself the authority to make it,” Wilson said. “Security rules written inside prompts may shape the model’s behavior, but they are still suggestions to the model, not enforceable security controls.”The gate has a price, and Wilson states it plainly. “The tradeoff is that the agent loses the ability to improvise arbitrary, high-impact infrastructure changes on its own, while retaining autonomous investigation and routine, bounded remediation,” he said.Why the No. 1 risk looks small in the record “Prompt injection is the best-understood LLM attack, and deployed systems defend against it actively,” the authors write, and they compress the whole divergence into one sentence. “Experts rank it first because the attack surface stays enormous even when the defenses mostly hold; the data sees the successes that got through.”Wilson has watched the gap from both sides of it. “Incident data is incredibly valuable, but it is inherently backward-looking and notoriously tricky to interpret,” he said. “It tells us what was observed, recognized, classified, and reported. It does not necessarily tell us what is most dangerous in the systems people are building right now.”He compares prompt injection to “death and taxes” and, increasingly, to “a law of physics for LLM systems,” because one model is being asked to interpret trusted instructions and untrusted content at the same time.Better defenses have not closed the case. “A control that works 99% of the time is not sufficient when the failure case gives an attacker meaningful access. And, frankly, I don’t think we are at 99%,” Wilson said. “The durable answer is not believing we can perfectly screen prompt injection out of existence. It is designing systems with the assumption that prompt injection will occur, understanding why it works, and limiting what an attacker can accomplish when it does.”A low advisory count can mean the defenses are working. It can just as easily mean nobody has looked, and the public record cannot tell a security team which one it is.The attempt volume is documented. CrowdStrike’s 2026 Global Threat Report found adversaries injected malicious prompts into legitimate GenAI tools at more than 90 organizations in 2025, stealing credentials and cryptocurrency, under a section titled “Prompts are the New Malware.” The telemetry shows pressure on the attack surface without proving defenses produced the No. 12 placement, but it is the pattern the mechanism predicts.The gap runs the other way too, and further Prompt injection is the headline case, and misinformation is the bigger one.The expert vote puts misinformation at No. 13, while the incident record places it at No. 2. The paper calls it “the widest disagreement between the two witnesses” and reports that its concordance flag “puts the probability that the two signals disagree at 99 percent.”The authors do not treat their own data as the winner. On misinformation they note the corpus “carries a large volume of deepfake and AI-generated disinformation,” records that often “describe harm produced by an AI rather than a vulnerability inside an LLM.” The authors call it the entry the record most disputes, stopping short of concluding the experts got it wrong.Where “too new to measure” runs into the CVE record The two brand-new taxonomy entries sit at the sharpest end. Persistent memory poisoning lands at expert No. 4 and incident No. 16, MCP tool interface exploitation at expert No. 7 and incident No. 16, each with an incident interval of 6 to 20 that spans most of the taxonomy.Public 2026 CVEs exist for both. On MCP tool interfaces, the Azure Data Explorer MCP Server carried KQL injection, and the CVE record describes it allowing “an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster,” scored 8.3 High. Kong’s Konnect MCP Server shipped an indirect prompt injection that lets a remote attacker steer the server into executing unintended API requests, the exact failure the MCP entry names.Agent memory has its own record. An agent harness, Ruflo, exposed unauthenticated MCP bridge endpoints that let a network attacker obtain a shell, read provider API keys, and poison the learning store, rated 10.0 Critical.The record is so thin and uncertain that the model cannot place either entry within 14 rank positions. A team waiting for advisory volume to justify a control on agent memory or an MCP tool boundary would still be waiting while the CVEs accumulate at Critical and High.Lambros makes the budget case in operational terms. Poisoned memory “doesn’t announce itself,” he said. It looks like a procurement agent told once that invoices from a given supplier under $50,000 clear without a second signature, and because the agent remembers, every approval after that looks like the process working. “Nobody files an advisory for that, because nobody knows it happened. A count of zero is measuring your blindness, not your safety.” The argument he says a CFO will sign off on is timing, since memory and tool permissions get wired into these systems once, early, and everything else sits on top of them. “Build it in now and it’s a rounding error. Come back in two years and you’re re-architecting and re-training your systems.”The authors flag their own measurement problems first The expert side is thin. “The expert signal is a practitioner survey: about 29 respondents scored each candidate risk on importance,” the authors write. Twenty-nine votes set the ranking that carries three-quarters of the published list’s weight, the compression point for OWASP’s more than 25,000 community members.On the data side, the classifier is the weak joint. Precision “varies sharply across entries, from 93% (LLM01, LLM03) down to 13% (LLM08),” four entries fall below 50%, and the base classifier “never predicts ‘out of scope’ and files every incident into some category, including the roughly 38% of the gold set that belongs in none.”The authors name the central limitation themselves. One reviewer adjudicated all 1,200 gold-set incidents and overrode the model consensus on 553 of them. “A single annotator cannot measure inter-rater reliability,” they write. “The single-author gold set remains the central limitation.”Lambros lays the weak kappa at the feet of the taxonomy itself. “That number is telling you about our categories, not about our experts,” he said. When the people who wrote a taxonomy cannot reliably sort incidents into it, he argues, “a weak score on the ordering of those buckets is a fact about the buckets.”A better classifier will not fix the disagreement. A pre-registered bake-off of four frontier models produced no winner. None beat the incidence floor’s balanced accuracy of 0.863, and a ground-truth check left the floor’s ordering in place at a Spearman correlation of 0.918. The authors published the engine and artifacts on GitHub for anyone to rerun.The robustness result tested only one side of the gap. Every check behind the abstract’s word “robust” runs on the incident side, showing the incident-derived ranking stays put when the labeling machinery changes, and none of it touches the 29-vote survey. A board that hears “robust” will assume validated, yet the record supports only stable.What the published list did with this OWASP shipped the GenAI LLM Top 10 2026 on August 4, the first edition to fold incident data into the ranking, weighting the practitioner vote at 75% and the incident corpus at 25%. Prompt injection stayed at No. 1, misinformation moved up two places, excessive agency climbed from No. 6 to No. 3 as the entry where the two signals agree most clearly, unbounded consumption rose four spots to No. 6, and improper output handling fell from No. 5 to No. 10, the largest drop.Wilson declines to defend the blend as arithmetic. “There is nothing magical about a 75/25 weighting,” he said, “or about reversing it to 25/75. The value of the data wasn’t that it gave us a mathematical answer; it changed the conversation.” The excessive agency entry is where that conversation landed hardest for him. “If I were a CISO evaluating a new agentic deployment today, Excessive Agency is where I would start,” Wilson said.Lambros would go further next cycle, a view he flags as his own and separate from the working group. The blend hands the same 25% incident weight to every category, while the hand-checked classifier precision runs from roughly nine in 10 on prompt injection and supply chain down to roughly one in eight on vector and embedding weaknesses. A quarter of the weight on the first rides on something solid, he argues, and the same quarter on the second rides on noise. “The ratio should track how well we actually measure each category,” Lambros said.Why this lands now Ivanti’s 2026 State of Cybersecurity research found 87% of security teams call adopting agentic AI a priority and 77% report at least some comfort letting AI act without human review. Teams are signing off on agent autonomy while the expert ranking of what can go wrong with those agents shows no statistically detectable agreement with the incident record.What to do with this on Monday The behavioral change is narrow and it is the whole point.Use the OWASP LLM Top 10 as a coverage map, not a queue. The rank positions carry 29 votes and a corpus whose own authors call the agreement weak, so build your own priority order from your own exposure: production reach, breach-notification data, and controls that have actually been tested. Lambros draws the funding line the same way. “I’d prioritize spend where the expert vote and the incident record point the same direction, because that’s two independent witnesses agreeing,” he said. “Where they split, stop letting the ranking allocate your money and go look at what your own systems are doing.”Log what your AI systems are actually doing, field by field. The prompt that went in, what came back out, the documents pulled to build the answer, the tools called and the arguments passed to them, and the model’s confidence score on every response. Confidence is the field Lambros would fight for, because most security leaders do not realize it is measurable, and it is where the attack surfaces. “A model running on a poisoned instruction doesn’t act broken. It acts certain,” he said. “Certainty is what your monitoring treats as a healthy system.” The cost is a sprint or two of engineering. The constraint is a person, because a SIEM does events and these are trends. “Somebody has to analyze those trends every week and say whether a drift means anything, and most security teams have nobody who can.”Stop expecting scanner output to reproduce the Top 10’s order. Scanner findings live on the incident side of the gap, counting what got disclosed rather than what a deployed system should fear, and the classifier bake-off shows a smarter model does not close that distance. The test that sees prompt injection is an adversarial one run against the live system, paired with Wilson’s authorization gate so the change an injected agent proposes is never the change it can execute.Fund the thin-record categories on architecture, not incident volume. Agent memory and MCP tool boundaries sit at expert No. 4 and No. 7 with incident intervals spanning most of the taxonomy, and the CVEs that do exist are landing at High and Critical. Kayne McGladrey, an IEEE senior member who advises enterprises on risk, put the funding logic bluntly in an interview with VentureBeat. “Anything that seems to have a cybersecurity flavor is generally put into the cybersecurity risk category, which is a complete fiction,” McGladrey said. “They should be focused on business risks, because if it doesn’t affect the business, like a financial loss, then nobody’s going to pay attention to it, and they will not budget it appropriately.” A rank number from a 29-person vote is a weaker budget argument than the business system the agent touches.Steal McGladrey’s baseline test for the AI systems themselves. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?” he said in CSO Online’s analysis of 2026 breach costs.The board question for the next meeting is short. If our AI risk ranking came from a 29-person vote and a corpus that disagrees with it, what are we actually using to decide which controls get funded next year?

Searching for Work? Adding This Overlooked One-Liner to Your Resume Could Help You Land the Job.

August 25, 2026 MMN Editor Filed Under: Uncategorized

Candidates are debating whether or not to include this section in their applications.

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 229
  • Page 230
  • Page 231
  • Page 232
  • Page 233
  • Interim pages omitted …
  • Page 295
  • Go to Next Page »

© 2026 Mad Mad News™ · OGGHY Media™ Live Above the Madness™ Independent news, signals, and analysis. Atlanta, Georgia