Chad Butler
banner
chadbutler.info
Chad Butler
@chadbutler.info
Founder, Entrepreneur, Product Security Leader, Husband, Dad, World Traveler.
My Mom gets these texts from scammers from time to time. Fortunately she always checks with me first.

I get a little buzz of anticipation because it means I get to waste the time of a scammer who was targeting my Mom. I strung the last one out for two days.
September 2, 2026 at 4:17 PM
Some people claim online courses are dead. Others claim you can make millions in passive income.

Both claims are garbage.

Two courses, 1,800 students, 97 countries, and no Lamborghini in my driveway. Getting rich is the worst reason to build one.
August 24, 2026 at 8:01 PM
My last job gave me an eye twitch.

I thought I'd hidden it well. A friend brought it up last week and I was surprised she'd noticed.

It stopped after the layoff. It stayed gone because I'd already started building something else.
August 24, 2026 at 12:03 AM
Ford, 2006. Every report was green. The company was losing $17B a year.

Most security programs build their dashboards the same way. Strategy, tools, scanning, then metrics.

Every metric exists to justify the program.

That's a vanity metric.
August 10, 2026 at 8:02 PM
More job applications, more silent rejections.

AI writes the resume. AI screens the resume. Same models on both ends.

I've been the one reading that pile. I don't want to be number 10 on your send list.

Somehow we forgot that people still hire people.
August 9, 2026 at 4:07 PM
A policy fight in the drone industry is turning into a cybersecurity and public safety story.

And there's a side to it you should know about.

I connect the dots in my latest video and newsletter article.
April 8, 2026 at 4:42 PM
Board view on AI browsers: goal is productivity without unmanaged risk. Reality: agentic browsers act with full session privileges; Gartner said block for now (Dec 2025) while controls catch up. Tradeoff: bans drive shadow use; broad rollout adds visibility + prompt risks. Decision: approve a tight
February 6, 2026 at 2:01 AM
OpenClaw went from obscurity to 158,000+ GitHub stars in weeks.

And, as always, it is tough to keep up with the pace of news.

I put together a summary for CISOs and shared it with my newsletter subscribers yesterday.

If you missed it, you can grab it here:
https://newsletter.missioninfosec.com
February 5, 2026 at 2:29 PM
3 questions to ask your team this week about FedRAMP 20x:

1. Can we generate machine-readable security documentation today?

2. Can our GRC tools generate OSCAL-compliant outputs natively?

3. What percentage of control validation could we automate right now?

The full breakdown in my newsletter.
January 27, 2026 at 4:03 PM
After 13 years of operation, only ~350 CSPs achieved FedRAMP authorization. The old model was broken.

FedRAMP 20x is the ground-up redesign. Automation-first. Continuous validation. Machine-readable artifacts.

Yesterday, my newsletter subscribers got the full breakdown.

Get the link below.
January 23, 2026 at 5:12 PM
FedRAMP 20x is the most significant shift in federal cloud authorization since the program began.

In tomorrow's Product Security Playbook issue, I'm covering:

1. Why a ground-up redesign was needed
2. The timeline through FY27
3. What is changing
4. The prep plan

Grab it with link below.
January 20, 2026 at 11:53 PM
Agentic AI browsers can read across tabs and take actions using your session.
So what: prompt injection becomes an “actions in authenticated sessions” risk.
Now what:
Mature = controlled pilot + detections.
Developing/Behind = block for now, find shadow use via DNS/SWG/EDR.
January 12, 2026 at 3:00 AM
Popular take: “We blocked AI browsers. Done.” My take: blocking is a phase, not the plan. Users bypass friction. Run a controlled pilot for low-risk workflows, set acceptable-use rules, and expand only when monitoring + controls meet IR needs. Link in comments.
January 3, 2026 at 2:01 AM
OpenAI Atlas is out of scope for SOC 2/ISO and doesn’t emit Compliance API logs or SIEM feeds.

If an incident hits an AI browser session, your audit trail may be thin. Do a control gap check (policy, logs, extensions, residency).

Big gaps: limited pilot. Controls comparison in comments.
December 26, 2025 at 7:01 AM
While researching for my next executive briefing on FedRAMP 20x, I encountered a major pet peeve.

The presenter was ignoring browser security warnings.

Reminder: please apply browser security patches before sharing your screen.

Lead and teach by example.

"Do as I say AND as I do."
December 16, 2025 at 4:50 PM
Gartner advised most orgs to block AI browsers for now. Agentic browsers can take real actions inside your logged-in sessions, turning prompt injection into action risk. Tomorrow: an exec briefing, missing controls, and a phased adoption plan in Product Security Playbook.
December 16, 2025 at 2:24 AM
Reposted by Chad Butler
🥳 IT BEGINS 🥳

The CactusCon 14 CFP is now OPEN!

sessionize.com/cactuscon-14/

Theme is an oldie but a goodie, regardless as usual we are looking for those juicy technical talks that make CactusCon great.

#cc14
CactusCon 14: Call for Speakers
Welcome to the CactusCon CFP!It's that time again - the CactusCon CFP is now open! We're looking for unique talks, workshops, and villages about hacki...
sessionize.com
September 6, 2025 at 2:01 PM
Reposted by Chad Butler
Booker finally yields after more than 25 hours of speaking 👏👏👏
April 2, 2025 at 12:08 AM
Reposted by Chad Butler
C-style strings in Rust should come with a disclaimer:

"This string has been handled in a facility that also processes uninitialized memory."
March 3, 2025 at 12:44 AM
Reposted by Chad Butler
➡️ January 20: FAA director fired
➡️ January 21: Air Traffic Controller hiring frozen
➡️ January 22: Aviation Safety Advisory Committee disbanded
➡️ January 28: Buyout/retirement demand sent to existing employees
➡️ January 29: First American mid-air collision in 16 years

Making America Great Again!
January 30, 2025 at 3:37 PM
“The only constant in my life is flash updates”

This channel is gold.

youtube.com/shorts/HDr9J...
*2000s PC Kid*
YouTube video by Programmers are also human
youtube.com
January 24, 2025 at 2:39 AM
The choice of wallpaper in this bathroom…
January 11, 2025 at 12:25 AM
Reposted by Chad Butler
yessssss join us students! and reasonably priced for everyone. we want everyone to be able to attend a quality cybersecurity con! <3
Hey… #CactusCon is Free to Students.

Students: send an email to [email protected] from your student email address to request a ticket.

@cactuscon.bsky.social will send you a promo code for one free student ticket. 🎟️ #LFG

www.cactuscon.com/cc13-tickets
CC13 Tickets — CactusCon
www.cactuscon.com
January 7, 2025 at 7:43 PM
Reposted by Chad Butler
"Last Xmas
I rsynced you my heart
And the very next day
rm -rf ~/heart
This year, to save me from tears
sudo chmod -r 000 ~/heart"
December 23, 2024 at 3:01 AM