Mission Control

Private — Faris Asmar

Mission Control
/
Faris Asmar · Sage AI
Last refreshed: Aug 15, 2026 10:55 UTCAuto-refreshes every 5 min · Cloudflare Pages
Logout
⚡ Quick Stats
LIVE ▼
Last Refresh
9m ago
last data refresh ▾
MC Content9m ago
Trading2702h ago
Research Briefs
7
of last 7 days ▾
✅ Thu Oct 01
✅ Wed Sep 30
✅ Tue Sep 29
✅ Mon Sep 28
✅ Sun Sep 27
✅ Sat Sep 26
✅ Fri Sep 25
Active Crons
23
scheduled tasks ▾
0 * * * *  ip_monitor.sh
0 * * * *  task-watchdog.log
0 5 * * *  nightly-research.log
0 6 * * *  goodreads-insights.log
0 11 * * *  boop.log
*/10 * * * *  mc-content-refresh.log
0 23 * * *  nightly-wrap.log
45 10 * * 0  weekly-synthesis.log
0 11 1 * *  null
0 7 * * *  telegram-briefs.log
0 22 * * *  inbox-monitor.log
0 12 * * *  boop-healthcheck.log
*/3 * * * *  cc_bridge_watchdog.sh
*/5 * * * *  telegram_health_cron.sh
0 13 1 * *  null
7 12 24 8 *  null
7 12 26 8 *  null
30 3 * * *  backup_civilization.sh
45 3 * * *  backup_secrets.sh
0 13 * * *  credit-monitor.log
Log Files
211
log files in /logs/ ▾
cc-bridge.log0m ago
mc-content-refresh.log9m ago
task-watchdog.log39m ago
credit-monitor.log39m ago
boop-healthcheck.log1h ago
boop.log2h ago
email_ingest.log3h ago
telegram-briefs.log6h ago
goodreads-insights.log7h ago
nightly-research.log8h ago
backup-secrets.log9h ago
backup-civilization.log10h ago
services.log12h ago
nightly-wrap.log14h ago
trading-daily-2026-09-30.log14h ago
...and 196 more
Sage Agent Roster
🤖 C-Suite Agents
ACTIVE ▼
Three C-suite advisors, each with 30+ years of domain depth. They run two ways. Nightly, they distill the intelligence brief into a role-specific digest. On demand, you hand one a question or a document and it answers in that executive's voice, grounded in the live intelligence it tracks. Ask the CISO to red-team a whitepaper, the CIO to build a buyer business case, the CTO to review an architecture.
💼
CTO
Chief Technology Officer — 30+ Years
Has navigated every architectural era: client/server through LLMs. Knows what holds under production load vs. what only works on whiteboards. Tracks nightly AI and cloud intelligence, and now advises on demand: hand it a design doc for an architecture review, a build vs buy call, or a stack and scaling sanity check. Grounds its counsel in today's market context, not generic best practice.
knowledge_aiops knowledge_cloud_platforms knowledge_digest On-Demand Advisor Architecture Build vs. Buy AI/ML Infra
🛡️
CISO
Chief Information Security Officer — 30+ Years
Has lived every major breach cycle from Morris Worm to SolarWinds to Log4j. Knows compliance vs. actual security posture, what SIG-Lite evaluators really score, and how to position AI governance as a competitive moat. Cites specific controls, never hedges. Tracks nightly threat intelligence, and now advises on demand: red-teams whitepapers and proposals, drafts security questionnaire answers, and gives you the buyer-side objections grounded in tonight's threats.
knowledge_cybersecurity knowledge_compliance_regulatory knowledge_digest On-Demand Advisor SOC 2 ISO 27001 SIG-Lite EU AI Act DLP
🖥️
CIO
Chief Information Officer — 30+ Years
Managed IT through Y2K, dot-com collapse, cloud disruption and COVID overnight remote. Knows Microsoft EA negotiation timing, why digital transformations fail, and what shadow IT signals. Speaks peer-to-peer with enterprise IT buyers. Tracks nightly IT, cloud and MSP intelligence, and now advises on demand: builds the buyer business case, pressure-tests pricing and packaging, and reviews proposals through the buyer's economics.
knowledge_it_infrastructure knowledge_cloud_platforms knowledge_msp knowledge_vendor_ecosystem knowledge_digest On-Demand Advisor IT Strategy MSP/MSSP Procurement
Automation Schedule
📅 Automation Schedule
ACTIVE ▼
Always Running
● PureBrain portal server
● Telegram bot (command listener)
● Trading daemon (trade alerts + 7 PM review)
● Email ingest daemon (polls every 5 min)
Daily (ET)
1:00 AM Nightly research → brief saved locally
IT Infrastructure · Cybersecurity · Cloud Platforms · NetDevOps · AI in Infrastructure · Hardware & GPU · Network Monitoring · MSP · IT Vendor & M&A · Edge & IoT
2:00 AM Reading insights generate (silent) → staged for 7:05 AM email
goodreads_insights.py — pulls from Faris's library, generates in his voice
7:00 AM Morning BOOP → Telegram
overnight trades, open positions, system health, unread emails
7:00 AM Industry intelligence brief → farisasmar@hotmail.com
7:05 AM Daily reading insights → farisasmar@hotmail.com & Muna_ers@hotmail.com
7:00 PM Nightly wrap → trading snapshot saved locally
7:00 PM Trading intelligence review → Telegram
strategy scorecard, coin rankings, risk analysis, weekly progress
Weekly
Sun 6:45 AM Weekly synthesis → farisasmar@hotmail.com
3 signals, 5 takeaways from week's research
Tue / Thu LinkedIn publish → 8:00 AM ET
on-demand: Faris picks story from morning brief → Sage generates post → approval → auto-posts
1st of month Goodreads export reminder → Telegram
Recurring
Every 5 min Trading bot watchdog + MC dashboard refresh
Every 10 min MC content refresh (Quick Stats, Intel Brief, Health, Reading Insights) + deploy
Hourly :00 IP monitor (Telegram if changed), task watchdog
PAUSED LinkedIn comment monitor (pending API approval)
LinkedIn Content Pipeline
LinkedIn Content Pipeline ACTIVE
Week of No posts
Next publish: All published
On-Demand Process
Pick a story from the morning intelligence brief → send to Sage → post generated immediately → queues for next Tue or Thu at 8 AM ET.
Tuesday
8 AM ET
Thursday
8 AM ET
Cynora Services Matrix — Content Reference ▾ expand
Never name Cynora. Never pitch. The reader finishes the post thinking 'this person knows this space deeply.' The Cynora angle lives in what the post reveals about how the problem is solved structurally — not in who solves it.
IT Infrastructure Management
Operational clarity and infrastructure discipline — what the environment looks like when it's managed with structure vs. when it drifts
› Organizations with managed infrastructure baselines catch problems in reviews, not incidents.
› The cost of reactive infrastructure management almost always exceeds the cost of proactive oversight.
› When no one owns the infrastructure picture end-to-end, everyone assumes someone else does.
› Technology debt doesn't disappear — it just ages into a different kind of risk.
Cybersecurity and Compliance
Pattern recognition across environments — what security looks like when you manage it across multiple organizations vs. a single one
› A security posture that depends on any single person's memory is already fragile.
› Compliance and security are not the same discipline — organizations that confuse them tend to pass audits and still get breached.
› Cross-environment visibility lets MSPs see threat patterns that single-company teams can't — each client environment becomes an early warning system for the others.
› The gap between 'we have security tools' and 'we have a security posture' is where most mid-market breaches live.
Cloud Strategy and Migration
The operational and governance layer above the technology — what cloud looks like when it's working vs. when it's just expensive
› Cloud migrations that succeed technically but fail operationally still fail.
› The organizations with the highest cloud spend are rarely the ones getting the most value from it.
› Moving infrastructure to the cloud without changing the governance model around it just moves the problem.
› FinOps discipline isn't about cutting cloud spend — it's about making sure the spend maps to business value.
Network Operations
Proactive vs. reactive network management — what the operational difference looks like at scale
› Most network incidents are visible in the data before they become user-facing problems — the question is whether anyone is watching.
› Network hardware end-of-life is a governance problem before it's a security problem.
› The organizations that treat network monitoring as overhead tend to find out the hard way that it's actually insurance.
› When the network team and the security team don't share visibility, gaps form exactly where attackers look first.
Helpdesk and End-User Support
What helpdesk operations reveal about the health of the broader IT environment — and what good service delivery governance actually looks like
› Helpdesk ticket volume is a symptom. The organizations that only measure resolution time often miss what the volume is telling them.
› Offshore support fails when selected on cost alone. Selected on fit — language, time zone overlap, technical depth — the cost advantage holds without the quality trade-off.
› Every offboarding gap is a security event waiting to happen. The organizations that treat it as an IT admin task rather than a governance requirement tend to find out eventually.
› Internal IT teams that handle Tier 1 support are spending strategic capacity on work that doesn't require it.
Vendor Management
Vendor governance as a strategic function — what changes when vendor relationships are actively managed vs. passively administered
› Most organizations don't know what their vendor portfolio costs or what it's delivering until something forces them to look.
› An SLA that measures response time without measuring resolution quality is measuring the wrong thing.
› Vendor relationships that go unreviewed don't stay static — they drift in the vendor's favor.
› The strongest IT organizations treat vendor management as a discipline, not an administrative function.
IT Governance and Advisory
The governance layer that makes technology investments coherent — what decisions look like when IT and business leadership share a framework vs. when they don't
› Organizations without a governance framework don't make fewer technology decisions — they make them with less information.
› The IT-business alignment gap rarely comes from lack of effort. It usually comes from IT reporting on activity when leadership needs visibility into risk and value.
› A technology roadmap that doesn't connect to business priorities isn't a roadmap — it's a wish list.
› The strongest IT leaders don't just manage technology. They translate between operational reality and business strategy.
Digital Transformation Advisory
The organizational and operational layer beneath the technology — what transformation looks like when it's designed around the business vs. when it's designed around the vendor's roadmap
› Digital transformation fails most often not because the technology doesn't work but because the organization wasn't ready to use it differently.
› AI adoption without workflow integration just creates a new layer of complexity on top of the existing one.
› The organizations that modernize successfully almost always sequence change management alongside technology delivery, not after it.
› A transformation program that can't articulate what business outcome it's moving toward isn't a transformation program — it's a technology upgrade.
Reading Insights
📚 Daily Reading Insights
DAILY ▼
October 1, 2026 — 3 books from your library
The 10X Rule: The Only Difference Between Success and Failure by Grant Cardone
Cardone's central argument is a calibration problem, not a motivation problem. Most people underestimate the effort required by a factor of ten, then interpret the resulting shortfall as evidence they lack talent or that the goal was wrong. The 10X Rule says to multiply your estimated effort by ten before you start, because friction, resistance and unforeseen complexity are structural features of any ambitious goal, not exceptions to it. The person who sets a realistic target and hits it has usually aimed too low and optimized for comfort. Massive action as a default posture removes the psychological negotiation that happens mid-effort, when normal people start reconsidering whether the goal is worth it.
Atomic Adventures: Secret Islands, Forgotten N-Rays, and Isotopic Murder by James Mahaffey
What Mahaffey keeps bringing up throughout the book is how often nuclear history was shaped by secrecy creating worse outcomes than transparency would have. Closed programs, buried test data and classified failures meant the same mistakes got repeated across agencies and nations, each one convinced they were pioneering territory that had already killed people somewhere else. The N-ray episode early in the book is a sharp case study in how institutional prestige corrupts the scientific process, where a respected physicist convinced himself and his colleagues they were observing a genuine phenomenon because disconfirming it would have been socially catastrophic. The isotope murder cases show that radiological knowledge in the wrong hands is dangerous not because the materials are easy to get, but because the symptoms they cause are easy to misread for weeks. Mahaffey's central subject is how much of nuclear history we've allowed to stay obscure, and what that ignorance costs.
Forex Trading Beginners Guide: Learn Strategies Every Top Trader is Using. Simple Step by Step Instructions on How to Develop A System That is Going to Work for You by Peter Massy
The structural insight in Massy's framework is that forex rewards systematic behavior over predictive behavior, meaning the goal is never to be right about where a currency pair goes, but to have a rule-set that captures asymmetric payoffs over a large sample. Most beginners treat each trade as an analytical challenge, a puzzle to solve, which collapses their decision-making under emotional load when the position moves against them. The discipline of defining entry, stop-loss and take-profit levels before executing forces the trader to operate on pre-committed logic rather than real-time rationalization. Position sizing relative to account equity is where most of the actual risk management lives, not in picking the right currency pair or reading the macro picture correctly. The system creates the edge, but consistency in applying the system is what separates traders who survive long enough to compound from those who blow accounts on high-conviction bets.
Sage Intelligence Brief
🧠 Intelligence Brief
NIGHTLY ▼
Brief date: Thursday, October 01, 2026
10 Research Domains
IT InfrastructureCybersecurity & ComplianceCloud PlatformsNetDevOps & AutomationAI in InfrastructureHardware, GPU & NetworkingNetwork MonitoringManaged Service ProvidersIT Vendor Ecosystem & M&AEdge Computing & IoT
SAGE INTELLIGENCE BRIEF Thursday, October 01, 2026 =========================================== LEAD STORY CVE-2026-76504 in Cisco Catalyst SD-WAN Manager is a CVSS 9.8 zero-day under active exploitation right now. A single crafted HTTP request with one percent-encoded character in the login path bypasses authentication entirely and gives the attacker API access as netadmin, no credentials required. Any internet-exposed SD-WAN Manager that hasn't been upgraded needs to have ports 443, 22 and 830 firewalled to known hosts immediately, tonight, before the upgrade window opens. --- CONNECTING THE THREADS Management-plane internet exposure as the root cause. I've been tracking this for weeks. MikroTik, Nexus 9000, Check Point and now Cisco SD-WAN Manager all falling to unauthenticated management-plane attacks in the same month. Tonight's SD-WAN Manager zero-day is another confirmation. The CVE mechanics change each time. The architecture failure is identical every time. Vendor-specific patching without pulling management planes off the internet is incomplete remediation, full stop. JWT signature bypass is becoming a pattern, not an anomaly. The JFrog Artifactory chain I flagged earlier validated unsigned JWTs to reach admin escalation. Tonight, the 16-year-old researcher's Microsoft Titan finding is structurally identical. Token contents validated, signature never checked, downstream access controls completely irrelevant. Two separate platforms, two separate teams, same fundamental implementation error. Any internal platform doing claim-based authorization needs to have signature enforcement explicitly confirmed, not assumed. NetScaler exploitation trajectory is accelerating. I flagged WHIPSHOT and SLAPSHOT targeting government and financial sectors across all verticals. Tonight's confirmation of active exploitation of CVE-2026-88771 and CVE-2026-88772 against the same sectors is the third signal this month pointing at NetScaler as a priority adversary target. The Mandiant guidance stands. Investigate before patching on any management-plane CVE with confirmed active exploitation. Patch-first on these is operationally wrong. --- IT INFRASTRUCTURE ARCHITECTURE RAM supply crunch is getting worse, not better Micron's CEO is celebrating "much higher" prices as supply tightens further. For anyone planning server refreshes or infrastructure buildouts in the next two to three quarters, memory cost assumptions in those budgets are going to be wrong. Pull procurement timelines forward where you can, and build cost escalation buffers into any quotes going out to clients right now. Source: https://www.theregister.com/systems/2026/10/01/ram-supply-set-to-worsen-says-micron-as-ceo-celebrates-much-higher-prices/5300346 Ubuntu 26.04 LTS upgrade prompts are live Canonical has started pushing upgrade notifications to Ubuntu 24.04 users. For any managed Linux fleet, now is the time to decide the upgrade policy before end users start accepting prompts on their own. Test the upgrade path in a staging environment this week, especially for any workloads running on customized kernel configs or third-party kernel modules. Source: https://www.theregister.com/os-platforms/2026/09/30/canonical-begins-pushing-resolute-raccoon/5300225 openSUSE Leap adds immutable mode OpenSUSE Leap now ships an immutable OS mode as a selectable security layer. This fits the broader pattern of declarative, reproducible OS configurations becoming an established enterprise control, worth watching for public sector RFPs in the next 18 months, where immutable OS posture is starting to appear as a procurement criterion. Source: https://www.zdnet.com/tech/opensuse-leap-immutable-mode-security/ --- CYBERSECURITY & COMPLIANCE Cisco SD-WAN Manager CVE-2026-76504: CVSS 9.8, actively exploited One crafted HTTP request with a percent-encoded character in the authentication path bypasses the entire auth rule and reaches the API as netadmin. All deployment models are affected. Cisco Cloud Managed instances are already patched at 20.15.605. On-prem operators: upgrade now, and restrict API ports to known hosts until the upgrade is complete. Detection requires manual log review in vmanage-server.log and vmanage-security.log for j_security_check entries from unauthorized IPs. Upgrading alone does not evict an attacker already inside. Source: https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html Microsoft Titan platform: JWT signature never verified, 17.3 trillion rows exposed A 16-year-old researcher found that Titan validated JWT claims but never verified the signature. Changing the UPN field to the string "admin" resolved to local user ID 1 with netadmin role. From there, 30 of 56 routing values were live, connecting to 17 analytics databases with 9,863 unique table names, plus employee org data and Bing telemetry. Microsoft patched and paid a $5,000 bounty. The operational lesson: signature verification must be enforced before any claim is trusted. Every internal platform doing claim-based authorization needs an explicit code review for this specific gap. Source: https://www.theregister.com/security/2026/09/30/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-173-trillion-rows/5300240 Zimbra CVE-2026-73570: web shells, RAT deployment and credential exfiltration CVSS 8.9, unauthenticated OS command injection via crafted SMTP when zimbra-snmp is installed. Attackers deployed JSP web shells, escalated to install the Zimclient2 Go-based RAT, extracted Zimbra credentials from localconfig.xml, exported database tables and staged them as final.tar.gz for exfiltration to Azure Blob via AzCopy. Patch is ZCS 10.1.20 (released July 20). If you can't patch immediately, uninstall zimbra-snmp right now. Audit webapps and temp directories for unauthorized files, and check /var/log/zimbra.log for unexpected service restarts. Source: https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html Malicious custom GPTs delivering RATs via ClickFix-style lures Threat actors are standing up custom GPTs on OpenAI's platform and using the legitimate OpenAI and Google domains as delivery infrastructure for remote access trojans. The trust signal of a known domain is doing the heavy lifting for the lure. User awareness training needs to explicitly cover this vector: a legitimate domain hosting the page does not make the payload legitimate. Source: https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure WatchGuard patches 15 critical Fireware OS vulnerabilities Code execution, DoS, authorization and path traversal bugs across Fireware OS. If you're running WatchGuard appliances in any managed environment, this is a mandatory update cycle, not optional. Pull the advisory, map affected firmware versions and get patching scheduled this week. Source: https://www.securityweek.com/ --- CLOUD PLATFORMS & STRATEGY Azure maintenance window broke hybrid clouds and VPNs Starting at 20:30 UTC on September 30, an Azure infrastructure OS servicing activity caused degraded performance across hybrid cloud connections, VPN gateways and Azure VMware Solution. Microsoft's post-incident summary acknowledges they're not fully certain how the maintenance activity caused the cascade. For any client with hybrid dependencies on Azure VPN gateways, this is a reminder that maintenance window communications from Microsoft need to feed into your change advisory process, not just arrive in an inbox. Source: https://www.theregister.com/off-prem/2026/10/01/azure-maintenance-mess-disrupted-hybrid-clouds-vpns-cloudy-vmware-services/5300333 AI coding agents leaked 13,000+ internal enterprise images to public GitHub repos AI coding agents asked to share screenshots for code review inadvertently exposed more than 13,000 internal images from developers at over 300 organizations, including customer billing records. Most ended up under personal developer accounts outside company security tooling visibility. This is a shadow IT data governance problem with active consequences. If your clients are running AI coding agents, you need a policy on what those agents can access and where their outputs go. Source: https://thehackernews.com/ NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 confirmed under active exploitation Government and financial sector organizations are being targeted in weeks-long campaigns. Sector-based threat modeling doesn't hold here. Any organization running NetScaler, regardless of industry, is a primary target. Patch status and investigation for existing compromise both need to happen in parallel. Source: https://www.securityweek.com/ --- NETDEVOPS & NETWORK AUTOMATION Cisco SD-WAN Manager actively exploited: detection and containment specifics Covered in full in Cybersecurity. No duplication here. Star Blizzard drops ClickFix, broadens phishing net Russia's Star Blizzard APT has moved away from ClickFix-style attacks and is running a wider phishing operation. The shift in TTPs suggests they're optimizing for volume over sophistication, which means a broader target set. Network teams should confirm DNS filtering and email gateway rules are current on Star Blizzard IOCs. Source: https://www.darkreading.com/threat-intelligence/russia-star-blizzard-ap --- AI IN INFRASTRUCTURE & AIOPS AI agents refactored 300K lines of C in three weeks for a fraction of human cost CodeScene published a case study where coding agents completed a 300,000-line C refactor in three weeks. The engineering practices question Peter Norvig raised is directly relevant here. The agents can move faster than the review and validation processes built around human-paced work. The risk shifts from code generation speed to verification and testing coverage. Source: https://www.infoq.com/news/2026/09/agentic-refactoring-case-study/ Google restricts Gemini 4 Argon access due to cybersecurity misuse risk Google is limiting Gemini 4 Argon to selected cybersecurity organizations while it tests safeguards. This is an early signal that frontier model capability is now advanced enough that the vendor itself is gating access on security grounds. For enterprise AI strategy, this is worth tracking. The access tier you can reach for frontier models may become a competitive differentiator. Source: https://techwireasia.com/2026/10/google-gemini-4-argon-cybersecurity-access --- HARDWARE, GPU & COMPUTE Huawei claims homegrown AI chip sales top Nvidia in China Eric Xu's claim is that Huawei's Ascend chips are outselling Nvidia inside China. Reliability of supply beats peak performance for domestic Chinese buyers, and export ban risk makes Nvidia a less dependable option. This is an important data point for anyone advising on AI infrastructure procurement with any China supply chain exposure. Source: https://www.theregister.com/systems/2026/09/30/huawei-boss-claims-homegrown-ai-chip-sales-top-nvidia-in-china/5300266 Gigabyte TRX50 AERO D: high-end workstation platform reviewed ServeTheHome reviewed the TRX50 AERO D targeting the high-end desktop segment. Relevant for any client building out AI workstation tiers or dense local inference environments where consumer-grade platform headroom matters. Source: https://www.servethehome.com/gigabyte-trx50-aero-d-motherboard-review/ --- NETWORK MANAGEMENT & MONITORING No notable developments tonight. --- MANAGED SERVICE PROVIDERS Pearson acquires Workera for AI skills assessment Pearson is acquiring Workera to help businesses identify AI skill gaps and target training. For MSPs positioning managed AI adoption services, this gives enterprise buyers a structured way to baseline their teams, which creates a natural conversation about who's handling the technical infrastructure side of that rollout. Source: https://www.zdnet.com/innovation/pearson-workera-acquisition-ai-upskilling/ SOC career ladder reshaping: satisfaction up, entry harder Swimlane research shows 91% of SOC practitioners report higher satisfaction with AI-assisted detection and response, but nearly half say the entry-level path has gotten harder. For MSPs building or maintaining a SOC capability, this is a hiring market signal. The junior pipeline is narrowing while the experienced tier is feeling better about their work. Plan compensation and sourcing strategy accordingly. Source: https://www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder --- IT VENDOR ECOSYSTEM & M&A OpenAI complains Chinese model distilled its training data OpenAI is alleging a Chinese model used its outputs as training data, while OpenAI's own training corpus is built on scraped web content. The policy argument being made is that distilling from a commercial model is a national security risk, while training on public internet data is standard practice. For enterprise buyers evaluating AI vendors, the IP provenance question is becoming a procurement and legal risk worth taking seriously. Source: https://www.theregister.com/security/2026/09/30/irony-alert-openai-whines-that-chinese-model-stole-its-special-ip-that-it-stole-from-everybody-else/5300285 iOS 27 launches Impersonation Risk Detection Apple's iOS 27 ships a setting called Impersonation Risk Detection that warns users of suspicious activity in communications. For any MSP managing mobile device fleets, this is a feature to communicate to clients and ensure it's enabled in MDM policy pushes. Source: https://www.zdnet.com/tech/ios-27-impersonation-risk-detection-security-feature/ --- EDGE COMPUTING & IOT No notable developments tonight. --- SALES & REVENUE Do your prospects trust you before you pitch? Most B2B buyers decide whether they'll engage seriously with a vendor in the first two conversations, before any solution has been presented. The practitioners who build rapport through curiosity rather than capability signaling close more, because buyers are willing to share genuine problems with them. The practical move is to spend the first conversation asking about outcomes and constraints, then spend the second one referencing what you heard before offering anything. Source: "Fanatical Prospecting" by Jeb Blount (Goodreads compounding) A client asks for ROI estimates in week two of a deal. You produce a number. They take it to finance and it falls apart. The number fell apart because it was built on your assumptions, not theirs. ROI models that survive internal scrutiny are built from the buyer's own metrics. Their current cost structure, their own productivity estimates, their existing benchmarks. Your job is to ask the questions that surface those numbers and then reflect them back. When the CFO challenges the model, the buyer can defend it because the inputs came from their own team. Source: "The Value Sale" by Ian Campbell (Goodreads compounding) Qualification is a filter, not a conversation. Most salespeople treat discovery as information-gathering for the pitch. Strong qualifiers treat it as a mutual assessment of whether a problem worth solving exists. If you can't name the specific business pain, the person accountable for it and the cost of leaving it unresolved, you haven't qualified. You've just had a pleasant meeting. Source: "Winning the Complex Sale" by Jeff Thull (Goodreads compounding) --- REAL ESTATE & INVESTMENT Sixty percent of commercial property insurance claims are disputed at least in part because the declared replacement cost at policy inception doesn't match actual rebuild costs at the time of loss. That gap is almost always the result of not updating insured values at renewal, especially after renovations or in high-inflation construction periods. If you haven't had an independent replacement cost appraisal on your commercial holdings in the last 24 months, your coverage is likely inadequate in ways the policy language won't protect you from. Source: "Property and Casualty Insurance: Concepts Simplified" by Christopher J. Boggs (Goodreads compounding) Pull the transit authority's published 5-year capital plan for any submarket you're underwriting before your next site visit. Planned transit infrastructure doesn't show up in current cap rate comparables, but it moves rents and vacancy in a predictable direction 24 to 36 months out. Submarkets with confirmed transit investment tend to absorb new supply better and attract a tenant quality that supports above-market rent growth. Most investors skip this step because it requires a separate research task. That's exactly why the edge is still there. Source: "The Complete Guide to Real Estate Investment" by Steve Berges (Goodreads compounding) A fund manager evaluating a value-add industrial portfolio in a secondary market ran the rent roll, confirmed in-place leases and stress-tested vacancy. The deal looked clean. Then he found that three of the five tenants were subsidiaries of the same parent company. A single credit event would have taken occupancy from 90% to 30% overnight. "The Real Estate Investor's Guide to Winning in Any Market" by Aram Shah uses this exact scenario to argue that tenant concentration risk is the underwriting variable most investors never put on their checklist because it requires reading lease abstracts, not just spreadsheets. The discipline to do the slow work when the deal looks good is what separates durable investors from ones who learn expensive lessons. Source: "The Real Estate Investor's Guide to Winning in Any Market" by Aram Shah (Goodreads compounding) --- SELF HELP, HUMAN PSYCHOLOGY & DARK PSYCHOLOGY The words you use to describe a setback to yourself determine how long it affects your performance. Labeling a failed deal or a missed deadline as "a disaster" versus "a setback I can correct" produces measurably different cortisol responses and recovery timelines. The internal narrative is a lever, not a symptom. Choosing more accurate, less catastrophizing language is precision. Cognitive reappraisal research covered in "The Emotional Intelligence Quick Book" by Travis Bradberry and Jean Greaves shows that practitioners who develop the habit of labeling accurately rather than intensely recover faster and make better decisions in the next window. Source: "The Emotional Intelligence Quick Book" by Travis Bradberry and Jean Greaves (Goodreads compounding) How do you know when someone's bad behavior is a personality issue versus a situational one you can change? The distinction matters enormously for how you respond. "Emotional Vampires" by Albert Bernstein makes the case that certain behavioral patterns, particularly those involving consistent exploitation of goodwill, poor reciprocity and escalation when confronted, are structural, not situational. The practical test: has the behavior persisted across multiple different circumstances and with multiple different people? If yes, you're dealing with a pattern, not a reaction. Managing the relationship accordingly means setting firm limits on access and information, not trying to fix the root cause. Source: "Emotional Vampires" by Albert Bernstein (Goodreads compounding) You've just taken over a team that's been underperforming for 18 months. The previous leader gave constant direction. Morale is low and people are waiting to be told what to do. "The Leader Who Had No Title" by Robin Sharma argues that the first intervention isn't a new strategy or a reset meeting. It's creating the conditions where people take ownership of something small and succeed at it publicly. Visible small wins rebuild the belief that effort produces results. Once that belief is partially restored, larger accountability becomes possible. Teams that have been over-directed need a win they own first. Source: "The Leader Who Had No Title" by Robin Sharma (Goodreads compounding) --- WHAT TO WATCH The management-plane exploitation pattern is compressing. SD-WAN Manager, NetScaler, Zimbra and Microsoft Titan all confirmed this week. The common thread is that authentication and authorization logic at the API layer is failing in ways that aren't caught until a researcher or an attacker finds them. Any management-plane system accessible from the internet without a jump host or IP restriction in front of it should be treated as the highest-priority remediation item in your environment right now. --- CONVERSATION STARTER A 16-year-old changed one field in an unsigned JWT from an email address to the string "admin" and got SQL execution rights against 17.3 trillion rows of Microsoft's internal analytics data. The vulnerability wasn't in the database or the network. The application never checked whether the token was valid. Ask your development teams today: where are we trusting claims without verifying the signature first? ===========================================
Trading — Paper Pilot
📈 Trading — Pilot v2 (Regime Adaptive) LIVE ↻ May 11, 2026 11:40 UTC
Portfolio Value
$3,184.00
Started $3,184.00
Gross P&L
$+0.00
0 closed trades
Total Fees
-$0.00
Entry & exit combined
Net P&L (After Fees)
$+0.00
Take-home profit
Return
+0.00%
vs starting capital
Win Rate
0%
0W / 0L
Today's P&L
$+0.00
Week 1: $+0.00
Avg P&L / Trade
$+0.00
Profit factor: 999.00x
Cash Available
$3,184.00
0 positions open ($0)
REGIME ADAPTIVE BTC + ETH only nbsp;· nbsp; Bull: Donchian 20d breakout nbsp;· nbsp; Neutral: RSI lt;33 dip buy nbsp;· nbsp; Bear: hold cash 60% per trade · 8% stop · Trailing @+7%
Portfolio Performance cumulative P&L by day
May 10   $3,184 Now   $3,184.00   (+0.00%)
Open Positions 0 open  ·  $0 deployed
SymbolStratQtyEntryCurrentStopRisk $Ret%Unrealized P&LStatus
No open positions
Strategy Breakdown closed trades only
StrategyTradesWLWin%Avg WAvg LGross P&LFeesNet P&L
Recent Trades (last 20) 🔄 trailing   🛑 hard stop   ⚖️ breakeven   🎯 target
SymbolStratQtyEntryExitRet%Gross P&LFeeNet P&LExitDate
Daily P&L bar scale = $50
DateResultsBarGross P&LFeeNet P&L
System Health
🟢 System Health
RUNNING ▼
Email Ingest daemon RUNNING
MC Content Refresh 9m ago OK
Trading Refresh 112d ago OVERDUE
Nightly Research 8h ago OK
Weekly Synthesis 4d ago OK
Reading Insights 7h ago OK
LinkedIn Posts 28d ago OVERDUE