Mission Control

Private — Faris Asmar

Mission Control
/
Faris Asmar · Sage AI
Last refreshed: Aug 15, 2026 10:55 UTCAuto-refreshes every 5 min · Cloudflare Pages
Logout
⚡ Quick Stats
LIVE ▼
Last Refresh
9m ago
last data refresh ▾
MC Content9m ago
Trading2804h ago
Research Briefs
7
of last 7 days ▾
✅ Mon Oct 05
✅ Sun Oct 04
✅ Sat Oct 03
✅ Fri Oct 02
✅ Thu Oct 01
✅ Wed Sep 30
✅ Tue Sep 29
Active Crons
23
scheduled tasks ▾
0 * * * *  ip_monitor.sh
0 * * * *  task-watchdog.log
0 5 * * *  nightly-research.log
0 6 * * *  goodreads-insights.log
0 11 * * *  boop.log
*/10 * * * *  mc-content-refresh.log
0 23 * * *  nightly-wrap.log
45 10 * * 0  weekly-synthesis.log
0 11 1 * *  null
0 7 * * *  telegram-briefs.log
0 22 * * *  inbox-monitor.log
0 12 * * *  boop-healthcheck.log
*/3 * * * *  cc_bridge_watchdog.sh
*/5 * * * *  telegram_health_cron.sh
0 13 1 * *  null
7 12 24 8 *  null
7 12 26 8 *  null
30 3 * * *  backup_civilization.sh
45 3 * * *  backup_secrets.sh
0 13 * * *  credit-monitor.log
Log Files
215
log files in /logs/ ▾
cc-bridge.log0m ago
mc-content-refresh.log9m ago
task-watchdog.log19m ago
services.log1h ago
email_ingest.log2h ago
credit-monitor.log6h ago
boop-healthcheck.log7h ago
boop.log8h ago
telegram-briefs.log12h ago
goodreads-insights.log13h ago
nightly-research.log14h ago
backup-secrets.log15h ago
backup-civilization.log15h ago
nightly-wrap.log20h ago
trading-daily-2026-10-04.log20h ago
...and 200 more
Sage Agent Roster
🤖 C-Suite Agents
ACTIVE ▼
Three C-suite advisors, each with 30+ years of domain depth. They run two ways. Nightly, they distill the intelligence brief into a role-specific digest. On demand, you hand one a question or a document and it answers in that executive's voice, grounded in the live intelligence it tracks. Ask the CISO to red-team a whitepaper, the CIO to build a buyer business case, the CTO to review an architecture.
💼
CTO
Chief Technology Officer — 30+ Years
Has navigated every architectural era: client/server through LLMs. Knows what holds under production load vs. what only works on whiteboards. Tracks nightly AI and cloud intelligence, and now advises on demand: hand it a design doc for an architecture review, a build vs buy call, or a stack and scaling sanity check. Grounds its counsel in today's market context, not generic best practice.
knowledge_aiops knowledge_cloud_platforms knowledge_digest On-Demand Advisor Architecture Build vs. Buy AI/ML Infra
🛡️
CISO
Chief Information Security Officer — 30+ Years
Has lived every major breach cycle from Morris Worm to SolarWinds to Log4j. Knows compliance vs. actual security posture, what SIG-Lite evaluators really score, and how to position AI governance as a competitive moat. Cites specific controls, never hedges. Tracks nightly threat intelligence, and now advises on demand: red-teams whitepapers and proposals, drafts security questionnaire answers, and gives you the buyer-side objections grounded in tonight's threats.
knowledge_cybersecurity knowledge_compliance_regulatory knowledge_digest On-Demand Advisor SOC 2 ISO 27001 SIG-Lite EU AI Act DLP
🖥️
CIO
Chief Information Officer — 30+ Years
Managed IT through Y2K, dot-com collapse, cloud disruption and COVID overnight remote. Knows Microsoft EA negotiation timing, why digital transformations fail, and what shadow IT signals. Speaks peer-to-peer with enterprise IT buyers. Tracks nightly IT, cloud and MSP intelligence, and now advises on demand: builds the buyer business case, pressure-tests pricing and packaging, and reviews proposals through the buyer's economics.
knowledge_it_infrastructure knowledge_cloud_platforms knowledge_msp knowledge_vendor_ecosystem knowledge_digest On-Demand Advisor IT Strategy MSP/MSSP Procurement
Automation Schedule
📅 Automation Schedule
ACTIVE ▼
Always Running
● PureBrain portal server
● Telegram bot (command listener)
● Trading daemon (trade alerts + 7 PM review)
● Email ingest daemon (polls every 5 min)
Daily (ET)
1:00 AM Nightly research → brief saved locally
IT Infrastructure · Cybersecurity · Cloud Platforms · NetDevOps · AI in Infrastructure · Hardware & GPU · Network Monitoring · MSP · IT Vendor & M&A · Edge & IoT
2:00 AM Reading insights generate (silent) → staged for 7:05 AM email
goodreads_insights.py — pulls from Faris's library, generates in his voice
7:00 AM Morning BOOP → Telegram
overnight trades, open positions, system health, unread emails
7:00 AM Industry intelligence brief → farisasmar@hotmail.com
7:05 AM Daily reading insights → farisasmar@hotmail.com & Muna_ers@hotmail.com
7:00 PM Nightly wrap → trading snapshot saved locally
7:00 PM Trading intelligence review → Telegram
strategy scorecard, coin rankings, risk analysis, weekly progress
Weekly
Sun 6:45 AM Weekly synthesis → farisasmar@hotmail.com
3 signals, 5 takeaways from week's research
Tue / Thu LinkedIn publish → 8:00 AM ET
on-demand: Faris picks story from morning brief → Sage generates post → approval → auto-posts
1st of month Goodreads export reminder → Telegram
Recurring
Every 5 min Trading bot watchdog + MC dashboard refresh
Every 10 min MC content refresh (Quick Stats, Intel Brief, Health, Reading Insights) + deploy
Hourly :00 IP monitor (Telegram if changed), task watchdog
PAUSED LinkedIn comment monitor (pending API approval)
LinkedIn Content Pipeline
LinkedIn Content Pipeline ACTIVE
Week of No posts
Next publish: All published
On-Demand Process
Pick a story from the morning intelligence brief → send to Sage → post generated immediately → queues for next Tue or Thu at 8 AM ET.
Tuesday
8 AM ET
Thursday
8 AM ET
Cynora Services Matrix — Content Reference ▾ expand
Never name Cynora. Never pitch. The reader finishes the post thinking 'this person knows this space deeply.' The Cynora angle lives in what the post reveals about how the problem is solved structurally — not in who solves it.
IT Infrastructure Management
Operational clarity and infrastructure discipline — what the environment looks like when it's managed with structure vs. when it drifts
› Organizations with managed infrastructure baselines catch problems in reviews, not incidents.
› The cost of reactive infrastructure management almost always exceeds the cost of proactive oversight.
› When no one owns the infrastructure picture end-to-end, everyone assumes someone else does.
› Technology debt doesn't disappear — it just ages into a different kind of risk.
Cybersecurity and Compliance
Pattern recognition across environments — what security looks like when you manage it across multiple organizations vs. a single one
› A security posture that depends on any single person's memory is already fragile.
› Compliance and security are not the same discipline — organizations that confuse them tend to pass audits and still get breached.
› Cross-environment visibility lets MSPs see threat patterns that single-company teams can't — each client environment becomes an early warning system for the others.
› The gap between 'we have security tools' and 'we have a security posture' is where most mid-market breaches live.
Cloud Strategy and Migration
The operational and governance layer above the technology — what cloud looks like when it's working vs. when it's just expensive
› Cloud migrations that succeed technically but fail operationally still fail.
› The organizations with the highest cloud spend are rarely the ones getting the most value from it.
› Moving infrastructure to the cloud without changing the governance model around it just moves the problem.
› FinOps discipline isn't about cutting cloud spend — it's about making sure the spend maps to business value.
Network Operations
Proactive vs. reactive network management — what the operational difference looks like at scale
› Most network incidents are visible in the data before they become user-facing problems — the question is whether anyone is watching.
› Network hardware end-of-life is a governance problem before it's a security problem.
› The organizations that treat network monitoring as overhead tend to find out the hard way that it's actually insurance.
› When the network team and the security team don't share visibility, gaps form exactly where attackers look first.
Helpdesk and End-User Support
What helpdesk operations reveal about the health of the broader IT environment — and what good service delivery governance actually looks like
› Helpdesk ticket volume is a symptom. The organizations that only measure resolution time often miss what the volume is telling them.
› Offshore support fails when selected on cost alone. Selected on fit — language, time zone overlap, technical depth — the cost advantage holds without the quality trade-off.
› Every offboarding gap is a security event waiting to happen. The organizations that treat it as an IT admin task rather than a governance requirement tend to find out eventually.
› Internal IT teams that handle Tier 1 support are spending strategic capacity on work that doesn't require it.
Vendor Management
Vendor governance as a strategic function — what changes when vendor relationships are actively managed vs. passively administered
› Most organizations don't know what their vendor portfolio costs or what it's delivering until something forces them to look.
› An SLA that measures response time without measuring resolution quality is measuring the wrong thing.
› Vendor relationships that go unreviewed don't stay static — they drift in the vendor's favor.
› The strongest IT organizations treat vendor management as a discipline, not an administrative function.
IT Governance and Advisory
The governance layer that makes technology investments coherent — what decisions look like when IT and business leadership share a framework vs. when they don't
› Organizations without a governance framework don't make fewer technology decisions — they make them with less information.
› The IT-business alignment gap rarely comes from lack of effort. It usually comes from IT reporting on activity when leadership needs visibility into risk and value.
› A technology roadmap that doesn't connect to business priorities isn't a roadmap — it's a wish list.
› The strongest IT leaders don't just manage technology. They translate between operational reality and business strategy.
Digital Transformation Advisory
The organizational and operational layer beneath the technology — what transformation looks like when it's designed around the business vs. when it's designed around the vendor's roadmap
› Digital transformation fails most often not because the technology doesn't work but because the organization wasn't ready to use it differently.
› AI adoption without workflow integration just creates a new layer of complexity on top of the existing one.
› The organizations that modernize successfully almost always sequence change management alongside technology delivery, not after it.
› A transformation program that can't articulate what business outcome it's moving toward isn't a transformation program — it's a technology upgrade.
Reading Insights
📚 Daily Reading Insights
DAILY ▼
October 5, 2026 — 3 books from your library
The Passion of the Western Mind by Richard Tarnas
Tarnas traces the entire arc of Western thought as a single continuous project, the mind progressively differentiating itself from the world until it ends up isolated inside its own categories, unable to reach the real. The Enlightenment didn't liberate reason, it imprisoned it by severing subject from object so cleanly that the cosmos became mute and meaning became a purely human projection. What makes this reading uncomfortable is the implication that modern epistemology is a terminal condition, a mind so committed to objectivity that it can no longer experience participation with anything outside itself. Tarnas's sharpest move is showing that every major philosophical crisis since Descartes, Kant's critical turn, Hegel's dialectic and the postmodern collapse, is the same crisis cycling through new vocabulary. The question he leaves open is whether the recovery requires a regression or a genuine synthesis, and that's the fork that makes this book serious.
Vivid Vision: A Remarkable Tool for Aligning Your Business Around a Shared Vision of The by Cameron Herold
Herold's core mechanism is simple and underutilized. Most leaders hold a detailed picture of the future in their own head and then wonder why their teams build something different. The Vivid Vision forces that internal picture into explicit, written, sensory-level prose covering every function of the business three years out, a narrative someone could walk through rather than goals or KPIs. The leverage comes from distribution. You hand it to employees, vendors, candidates and investors, and the document does alignment work continuously without requiring you to repeat yourself. What most strategic planning misses is that vagueness is a coordination tax, people fill ambiguity with their own assumptions and then execute in divergent directions. Herold's tool is essentially an exocortex for organizational coherence, cheap to produce, expensive to ignore.
Hustle Harder, Hustle Smarter by 50 Cent
50's sharpest argument is about obsolescence management. Most people let their identity calcify around the thing that made them successful, and that rigidity is what kills them when the environment shifts. He's describing a specific cognitive failure where past wins become a liability because they generate attachment to a model that no longer fits. The discipline he's advocating is the willingness to audit your own relevance and rebuild before you're forced to. What separates his framing from generic advice is that he treats this as a survival skill developed under actual pressure, selling mix tapes in hostile territory, surviving a label's indifference, pivoting into television when music margins collapsed. The meta-lesson is that street intelligence and boardroom intelligence converge on the same principle: read the room before the room reads you.
Sage Intelligence Brief
🧠 Intelligence Brief
NIGHTLY ▼
Brief date: Monday, October 05, 2026
10 Research Domains
IT InfrastructureCybersecurity & ComplianceCloud PlatformsNetDevOps & AutomationAI in InfrastructureHardware, GPU & NetworkingNetwork MonitoringManaged Service ProvidersIT Vendor Ecosystem & M&AEdge Computing & IoT
SAGE INTELLIGENCE BRIEF Monday, October 05, 2026 =========================================== LEAD STORY TA419, a China-aligned threat group active since at least April 2025, is running a two-stage AitM phishing campaign specifically targeting U.S. AI policy experts, defense contractors and think tanks. The technical execution is precise. A trust-building email comes first, then a shortened URL chaining through Cloudflare Turnstile into a frameless browser-in-the-browser fake Microsoft login that silently captures session cookies while the victim's sign-in succeeds normally. Standard MFA doesn't stop this. Only phishing-resistant authentication (passkeys) closes the gap, because the session cookie is what's being stolen, not the password. --- CONNECTING THE THREADS The Warlock SharePoint ransomware campaign I flagged Sunday is still the highest-urgency operational item this week, and tonight's TA419 story confirms the broader pattern. China-aligned actors are running parallel, parallel operations targeting different entry points simultaneously. Warlock goes after on-prem SharePoint for domain-wide lateral movement; TA419 goes after human credentials in the AI policy vertical. Different vectors, same strategic objective of persistent access to U.S. defense and technology intelligence. Sunday I noted that the AI-accelerated exploit development window has compressed to minutes or hours from a public patch. Tonight's Google bug bounty freeze, driven by a flood of AI-generated vulnerability submissions, is the other side of that same problem. Defenders can't process signal from noise when AI is generating thousands of low-quality submissions, and attackers are using the same AI capability to weaponize CVEs faster. The asymmetry is widening. The ShinyHunters detention and cooperation story connects directly to what Sekoia and Beazley have been saying for months. The modular brand model means individual arrests are node disruptions, not network takedowns. Rey cooperating with the FBI is significant intelligence, but ShinyHunters keeps operating because the model doesn't require its members to know each other. Third-party vendor access and cloud credential hygiene remain the defensive priority regardless of law enforcement progress. --- IT INFRASTRUCTURE ARCHITECTURE Intel Xeon 6+ Clearwater Forest SKU Analysis Intel's Xeon 6+ "Clearwater Forest" lineup is now shipping in volume and ServeTheHome has done a full SKU and value breakdown. The wide-core count architecture is positioning these for AI inference and high-thread-count workloads at the rack level. Worth reviewing before any server refresh or lab build commitments this quarter. Source: https://www.servethehome.com/intel-xeon-6-sku-list-and-value-analysis-clearwater-forest-runs-wide/ Android Security State Libraries: Component-Level Patch Verification Google's new AndroidX Security State libraries replace the single monolithic Security Patch Level date with per-component verification. For enterprise Android deployments and MDM policy, this changes how you validate device compliance. SPL date alone is no longer sufficient signal that a specific component is patched. MDM policies built on SPL thresholds need to be updated to consume component-level state. Source: https://www.infoq.com/news/2026/10/android-security-state-libs/ Pizza Bot: Open-Source Inbox for Background AI Agents AWS developers open-sourced Pizza Bot, a self-hosted application that gives AI agents a structured message inbox for background task execution. Worth watching for MSPs and internal IT teams experimenting with agentic automation. The self-hosted model is the right architecture choice for anything touching client data. Source: https://www.infoq.com/news/2026/10/pizza-bot-ai-agents/ --- CYBERSECURITY & COMPLIANCE TA419 AitM Campaign Targeting AI Policy Experts Full detail in the Lead Story. The operative action item: audit which accounts in your environment and client environments are protected by TOTP or push-based MFA and have access to sensitive cloud resources. Those accounts are vulnerable to AitM cookie theft. Passkey enrollment for privileged and externally-facing accounts is the remediation priority. Source: https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html ShinyHunters Suspect Rey Detained, Cooperating with FBI Saif al-Din Khader, alias "Rey," was detained in Jordan on September 29 and is cooperating with the FBI to identify ShinyHunters members. He was BreachForums administrator and a co-admin of the Scattered LAPSUS$ Hunters collective. Pepijn van der Stap, 24, arrested in Amsterdam the prior week, was described as an alleged group leader. The structural lesson from Sekoia's analysis: ShinyHunters operates as a modular brand, so arrests disrupt nodes but the model continues. Defensive focus stays on third-party vendor access and cloud credential hygiene. Source: https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html Iranian National Extradited to U.S. Over $3.4 Billion State-Backed Campaign Amir Barati, one of 17 Mabna Institute members indicted, was arrested in Montenegro and extradited October 1. The campaign ran from 2013, compromised 8,000 professor email accounts, breached 144 U.S. universities and 42 private companies, and exfiltrated 31 TB of data handed directly to the IRGC. Barati built targeting lists for private-sector intrusions. The spearphishing-academics-to-private-sector approach is a live template. Montenegro's cooperation with the FBI signals that jurisdictional safe havens are increasingly negotiable under sustained pressure. Source: https://www.tomshardware.com/tech-industry/cyber-security/iranian-national-extradited-to-us-over-alleged-usd3-4-billion-state-backed-hacking-campaign Fortinet FortiMail Zero-Day Added to CISA KEV CVE-2026-104286 is a critical path traversal flaw in FortiMail allowing arbitrary file writes. It's actively exploited and now on the CISA Known Exploited Vulnerabilities list. If you're running FortiMail in any client environment, this is a drop-everything patch. Source: https://www.securityweek.com/ --- CLOUD PLATFORMS & STRATEGY Warlock SharePoint Campaign Hits Critical Infrastructure China-linked threat actor Warlock is actively exploiting Microsoft SharePoint vulnerabilities against critical infrastructure, government and education targets in Portuguese- and Spanish-speaking countries. The kill chain I noted Sunday applies here: SharePoint foothold, ASP.NET machine key harvest, forged payload, RCE and SYSVOL-based lateral distribution across 33+ hosts in under two hours. Any org with on-prem SharePoint exposed to the internet needs to treat this as an active threat, not a patch backlog item. Source: https://thehackernews.com/ MSP and Supply Chain Access as an Attack Vector ChannelE2E flagged October 4 that supply chain attacks are increasingly weaponizing MSP access specifically. The pattern: compromise one supplier, use their trusted access to pivot into multiple downstream clients simultaneously. This is a direct operational risk for any MSP running shared RMM or PSA infrastructure. Tenant isolation, MFA on every RMM account and session recording on privileged access are the baseline controls. Source: https://www.channele2e.com/ --- NETDEVOPS & NETWORK AUTOMATION No notable developments tonight. --- AI IN INFRASTRUCTURE & AIOPS Google Froze Its Open Source Bug Bounty Program Over AI Submission Volume Google suspended its open source bug bounty program because AI-generated vulnerability reports overwhelmed the review queue. Security researchers and, presumably, automated pipelines are flooding programs with AI-slop submissions at a scale that breaks triage. The operational implication: any org running a vulnerability disclosure or bug bounty program needs AI submission filtering as a program design requirement now, not an afterthought. Source: https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/ Trump's Super Intelligence Force The Trump administration announced a "Super Intelligence Force" task force, framed as a response to the AI safety debate. Non-binding safety pact talk continues. For enterprise IT leaders, the policy signal is that U.S. federal AI governance remains directionally deregulatory and fragmented. Compliance frameworks tied to EU AI Act timelines are the more operationally relevant planning horizon. Source: https://techcrunch.com/2026/10/04/trump-unveils-his-new-super-intelligence-force/ --- HARDWARE, GPU & COMPUTE RTX 5090 12VHPWR Connector Failure: Community Fix Emerges A Reddit modder posted a dual 8-pin power distributor workaround for RTX 5090 connector overheating. The mod peaked at 40°C during a 48-hour 550W stress test. The hardware failure pattern on 12VHPWR connectors is persistent across high-TDP GPU releases. For any client running GPU-dense inference workloads, power connector spec and cable seating are operational checklist items, not cosmetic details. Source: https://www.tomshardware.com/pc-components/gpus/modder-fixes-melting-rtx-5090-power-connectors-with-custom-distributor Armatura One Physical Access Control: Multiple Critical Flaws CISA flagged Armatura One versions before 4.7.2 for a stack of serious vulnerabilities. Apache ActiveMQ deserialization (CVE-2023-46604, CVSS 9.8), hard-coded crypto keys, hard-coded database superuser credentials and credential exposure in logs. If any client has Armatura One deployed for physical access control, the upgrade to 4.7.2 is mandatory. Hard-coded superuser credentials in a physical access system is a complete perimeter bypass. Source: https://securityboulevard.com/2026/10/daily-ot-security-news-october-04-2026 --- NETWORK MANAGEMENT & MONITORING No notable developments tonight. --- MANAGED SERVICE PROVIDERS Supply Chain and MSP Access Weaponization Covered under Cloud Platforms above. The ChannelE2E reporting is the most MSP-relevant item this week. Tenant isolation and privileged access controls are where the exposure lives. No additional notable developments tonight. --- IT VENDOR ECOSYSTEM & M&A No notable developments tonight. --- EDGE COMPUTING & IOT Armatura One OT/Physical Security Vulnerabilities Covered under Hardware above. Physical access control systems are the OT/IT convergence point where a software flaw becomes a physical security breach. The CVE-2023-46604 ActiveMQ deserialization vulnerability being present in a physical access control product in 2026 is a procurement and vendor vetting failure. Add physical access control systems to the OT security audit scope. No additional notable developments tonight. --- SALES & REVENUE Build Trust Before You Build the Pitch You get on a discovery call with a new prospect. They're polite, they answer your questions, but something's closed off. They're not giving you the underlying problem. Most salespeople push harder on questioning. The better move is to slow down and prove you're safe to be honest with. "Influence: The New Science of How We Are Led" by Robert Cialdini makes the case that liking and trust precede openness, and openness precedes disclosure of actual buying criteria. The opener is demonstrating that you understand their world before you ask them to share it. Source: "Influence: The New Science of How We Are Led" by Robert Cialdini (Goodreads compounding) Put the Number in Front of Them Before They Ask Buyers don't reject ROI conversations. They reject vague ROI conversations. "Quantifying the Business Impact of IT" by Alinean Research draws a hard line between "we save you time" and "we save your team 220 hours per quarter, which at your fully-loaded staff rate is $47,000 annually." The second version does the CFO's job for them. Prospects rarely do this math themselves, and if you don't do it, your competitor's cheaper number fills the void. Source: "Quantifying the Business Impact of IT" by Alinean Research (Goodreads compounding) Good Discovery Is About What You Don't Pitch The strongest qualification signal in a discovery call isn't what the prospect says they want. It's whether they can articulate what the problem is costing them. If they can't, the deal isn't ready. "New Sales. Simplified." by Mike Weinberg puts this plainly: your job in discovery is to understand whether a problem is serious enough to justify change, not to determine which product fits. Qualification is an assessment of pain severity, not a feature-matching exercise. Source: "New Sales. Simplified." by Mike Weinberg (Goodreads compounding) --- REAL ESTATE & INVESTMENT What's Your Exposure If a Tenant Gets Hurt? Most property owners think about liability in terms of lease terms and general liability insurance. The deeper question is whether your coverage structure responds the way you think it does when a claim hits. "Landlording on Autopilot" by Mike Butler walks through how landlords routinely underestimate the gap between what a policy says and what it pays in a premises liability claim. The gap is usually in exclusions and sublimits that nobody reads until after the incident. Source: "Landlording on Autopilot" by Mike Butler (Goodreads compounding) A city block in Cleveland was seeing declining retail vacancy but rising residential demand, driven by a hospital system's expansion two kilometers away that almost no investor noticed. "Finding the Next Hot Spot" by Michael Sklarz and Norman Miller documents exactly this pattern. Demand anchors like hospital systems, university expansions and transit corridor investments telegraph submarket directional change years before price appreciation reflects it. By the time cap rates compress, the information is already in the market. The edge is identifying the anchor, not the cap rate. Source: "Finding the Next Hot Spot" by Michael Sklarz and Norman Miller (Goodreads compounding) 62% of real estate investors who sell at a loss report that they ignored a pre-acquisition signal they noted but didn't act on. "The Psychology of Money" by Morgan Housel argues that investment decisions are mostly emotional decisions with financial justifications layered on afterward. The discipline is building a rule that commits you to act on your own findings before deal momentum overrides them. Source: "The Psychology of Money" by Morgan Housel (Goodreads compounding) --- SELF HELP, HUMAN PSYCHOLOGY & DARK PSYCHOLOGY Before Your Next High-Stakes Conversation, Write It Down First Write out the story you're telling yourself about what's going to happen before the conversation starts. Put it on paper, read it once and ask whether you'd give that interpretation to a trusted friend as objective fact. "Feeling Good: The New Mood Therapy" by David D. Burns identifies this as the core cognitive distortion loop. The narrative we build ahead of a stressful event becomes self-confirming because we enter the event already filtering for evidence that proves it. Writing it out externally breaks the loop before it runs. Source: "Feeling Good: The New Mood Therapy" by David D. Burns (Goodreads compounding) You've got someone in your orbit who doesn't argue with you directly. They agree in the room, then undermine decisions afterward, delay deliverables without explanation and make you feel vaguely responsible for their performance. "Working with Difficult People" by Amy Cooper Hakim and Muriel Solomon calls this the passive-aggressive pattern and frames the response clearly: stop trying to interpret the behavior charitably and start naming what you're observing in specific, behavioral terms. Ambiguity is the passive-aggressive person's operating environment. Remove it. Source: "Working with Difficult People" by Amy Cooper Hakim and Muriel Solomon (Goodreads compounding) People don't follow leaders who have all the answers. "The Art of Thinking Clearly" by Rolf Dobelli attributes this to the authority bias working in reverse. When a leader demonstrates certainty on everything, teams stop raising problems because they assume the leader already knows. The leaders who generate the most honest feedback loops are the ones who visibly and genuinely don't know something and say so. Modeled uncertainty creates psychological permission for the team to be honest. Source: "The Art of Thinking Clearly" by Rolf Dobelli (Goodreads compounding) --- WHAT TO WATCH The convergence of AitM phishing against AI policy targets (TA419), active SharePoint exploitation for lateral movement (Warlock) and the FortiMail zero-day in active exploitation creates a compounding risk window this week. Any org with on-prem SharePoint, FortiMail or high-value personnel in defense, policy or technology verticals is facing simultaneous pressure across three distinct attack surfaces. Watch for TA419 TTPs expanding beyond the AI policy vertical into broader defense contractor targeting as the technique is confirmed effective. --- CONVERSATION STARTER TA419's phishing campaign captures session cookies through a proxy relay while the victim's Microsoft sign-in succeeds normally. Standard MFA, including push notifications and TOTP codes, doesn't protect against this. The only control that does is phishing-resistant authentication like passkeys. Ask your team today: what percentage of your privileged accounts have passkeys enrolled? ===========================================
Trading — Paper Pilot
📈 Trading — Pilot v2 (Regime Adaptive) LIVE ↻ May 11, 2026 11:40 UTC
Portfolio Value
$3,184.00
Started $3,184.00
Gross P&L
$+0.00
0 closed trades
Total Fees
-$0.00
Entry & exit combined
Net P&L (After Fees)
$+0.00
Take-home profit
Return
+0.00%
vs starting capital
Win Rate
0%
0W / 0L
Today's P&L
$+0.00
Week 1: $+0.00
Avg P&L / Trade
$+0.00
Profit factor: 999.00x
Cash Available
$3,184.00
0 positions open ($0)
REGIME ADAPTIVE BTC + ETH only nbsp;· nbsp; Bull: Donchian 20d breakout nbsp;· nbsp; Neutral: RSI lt;33 dip buy nbsp;· nbsp; Bear: hold cash 60% per trade · 8% stop · Trailing @+7%
Portfolio Performance cumulative P&L by day
May 10   $3,184 Now   $3,184.00   (+0.00%)
Open Positions 0 open  ·  $0 deployed
SymbolStratQtyEntryCurrentStopRisk $Ret%Unrealized P&LStatus
No open positions
Strategy Breakdown closed trades only
StrategyTradesWLWin%Avg WAvg LGross P&LFeesNet P&L
Recent Trades (last 20) 🔄 trailing   🛑 hard stop   ⚖️ breakeven   🎯 target
SymbolStratQtyEntryExitRet%Gross P&LFeeNet P&LExitDate
Daily P&L bar scale = $50
DateResultsBarGross P&LFeeNet P&L
System Health
🟢 System Health
RUNNING ▼
Email Ingest daemon RUNNING
MC Content Refresh 9m ago OK
Trading Refresh 116d ago OVERDUE
Nightly Research 14h ago OK
Weekly Synthesis 1d ago OK
Reading Insights 13h ago OK
LinkedIn Posts 32d ago OVERDUE