Sunday Signal: Why Cybersecurity and AI Literacy Belong in Climate Work

Every Sunday I set aside time to work through the week’s news and updates in artificial intelligence and cybersecurity. It is not a hobby and it is not doom-scrolling. It is preparation. Running websites, online communities, email systems, and public-facing climate-education projects means that the decisions I make about technology affect other people — their privacy, their data, and the trust they place in this work.

Being informed about these two subjects lets you decide from a position of judgment rather than urgency, marketing, or fear. That distinction is the whole point of this post. Below is the framework I use, the reading stack I recommend, and — because it matters — a note on how every link here was checked before publishing.

Why Cybersecurity Matters

Cybersecurity is not merely an IT concern. It is operational resilience. A compromised WordPress site, administrator email account, payment tool, domain registrar, mailing list, or cloud drive can interrupt your work, expose community-member information, damage your reputation, and consume enormous time to repair. For a small organization, that time is the scarcest resource there is.

Telling the Difference

Being well informed helps you distinguish between:

  • A genuine security alert and a phishing email designed to steal credentials.
  • A useful plugin, browser extension, AI service, or marketing platform and one that introduces unnecessary tracking, malware, data exposure, or account risk.
  • A low-priority technical headline and an urgent, actively exploited vulnerability affecting software you actually use.
  • A cheap hosting, membership, email, or payment service and one with inadequate security practices, weak account controls, or poor breach response.
  • A persuasive “urgent” request from a vendor, collaborator, or apparent community member and a social-engineering attempt.

What the FTC Recommends for Small Organizations

The Federal Trade Commission’s small-business cybersecurity guidance organizes this work around the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. Under Govern, the FTC advises organizations to understand how cyber risks could disrupt their mission, assess the risks posed by suppliers and third parties before entering formal relationships, and create and enforce a written cybersecurity policy. Under Protect, it recommends multi-factor authentication for everyone with access, regular backups, limits on who can reach sensitive assets, and training so that every person using your systems can recognize common attacks and practice basic cyber hygiene.

On phishing specifically, the guidance is refreshingly concrete: look up the company independently rather than using the link or number you were sent, hover over links before clicking, and pick up the phone using a number you already know to be correct. Read the FTC guidance.

Better Decisions in Practice

DecisionLess-informed approachWell-informed approach
Choosing softwareInstall a promising plugin or app immediatelyCheck vendor reputation, update history, permissions, privacy policy, security disclosures, and whether the feature is worth the new attack surface
Handling emailAct on an “urgent” domain, invoice, password-reset, or payment requestVerify through a known-good website, saved contact method, or second channel before clicking, paying, or changing account access
Managing accountsReuse passwords or rely on a password aloneUse a password manager, unique passwords, multi-factor authentication, saved recovery codes, and as few administrator accounts as possible
Buying servicesChoose the least expensive host, newsletter tool, or member platformWeigh security controls, backups, account recovery, data location, vendor access, export options, and incident-response quality
Responding to newsPanic after every breach headlineIdentify whether you use the affected product, update or mitigate if necessary, then document what changed

Routines That Actually Hold

For projects like mine, awareness turns into a handful of repeatable habits: keep WordPress, themes, plugins, and server components patched; maintain tested backups that are not connected to the live system; enable multi-factor authentication on the domain registrar, email, cloud storage, hosting, and finance accounts; and steadily reduce the number of people and plugins holding administrator-level access. None of this is glamorous. All of it is cheaper than recovery.

Why AI Matters

AI is becoming a general-purpose layer across publishing, search, customer support, design, education, advertising, website tools, and workplace software. Being informed helps you decide where AI genuinely improves your work, where it merely adds noise, and where its use would create unacceptable privacy, accuracy, bias, copyright, or reputational risk.

What “Trustworthy” Means in Practice

NIST’s AI Risk Management Framework treats trustworthy AI as considerably more than raw capability. It identifies seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. NIST is explicit that these characteristics trade off against one another, that a highly secure but unfair system is still a bad system, and that trustworthiness is only as strong as its weakest characteristic. Read the NIST characteristics.

In plainer terms: a tool can produce impressive-looking output and still be a poor choice for a real community, a public-facing publication, or an educational program. Worth noting for anyone citing this framework — NIST has posted that AI RMF 1.0 is being updated and a revised version is in progress, so check the source rather than relying on a summary written a year ago.

Better Decisions in Practice

DecisionLess-informed approachWell-informed approach
Selecting an AI toolChoose the most viral or the cheapest optionCompare privacy terms, data retention, training-use policies, export controls, security, cost, reliability, and the provider’s transparency
Publishing AI-assisted materialAssume fluent output is accurateFact-check claims, retain source links, flag uncertainty, and apply human editorial review before publication
Using member or customer dataPaste messages, emails, health details, or personal records into a chatbotMinimize sensitive inputs, obtain appropriate permission, use privacy-preserving settings, and avoid tools whose terms do not support that use
Automating community workLet automation decide who receives help, visibility, moderation, or priorityKeep people in the loop for consequential decisions; test outputs for errors, unfairness, and harmful edge cases
Evaluating AI claimsBelieve “AI-powered” means betterAsk: What task does it improve? Compared with what baseline? What data does it use? What can go wrong? Who is accountable?

Where the Two Subjects Meet

These fields are converging. AI can strengthen defense by helping analyze logs, prioritize alerts, summarize threat reports, and improve documentation. It also makes phishing, impersonation, fake imagery, voice cloning, social engineering, malicious code generation, and misinformation cheaper and far more convincing.

A message that once looked obviously fraudulent may now be polished, personalized, and written in a familiar tone. It may arrive with a convincing voice note or video likeness. The durable habit is therefore not “spot the bad grammar.” It is verify important requests through an independent channel — especially anything involving money, passwords, MFA codes, account recovery, urgent file sharing, domain transfers, or changes to banking and payment details.

The New Attack Surface

There is also a category of risk that did not exist a few years ago. The OWASP GenAI Security Project maintains a Top 10 for LLM Applications covering the failure modes specific to AI systems — prompt injection, sensitive information disclosure, supply-chain risk, data and model poisoning, improper output handling, excessive agency, system-prompt leakage, and unbounded consumption among them. See the OWASP list.

Two items deserve special attention from anyone running a website or community. Prompt injection means untrusted text — a web page, a document, an email, a comment on your own site — can be read by an AI tool as an instruction rather than as content. Excessive agency means giving an AI assistant more permission to act than the task requires. Both risks grow sharply the moment you connect an AI tool to your inbox, your files, your browser, or your site’s admin panel. The safe default is to grant the narrowest access that gets the job done, and to keep a human approval step in front of anything irreversible.

A Decision Framework You Can Use

Before adopting a new AI tool, responding to a security event, or approving a new digital service, ask five questions.

  1. What problem does this solve? Define the outcome first — faster research, better graphics, member support, transcription, security monitoring, content planning — rather than adopting technology because it is fashionable.
  2. What data will it touch? Include member information, email lists, login data, unpublished drafts, financial records, donor records, analytics, and sensitive communications.
  3. What is the credible downside? Consider inaccurate content, privacy leakage, account compromise, vendor lock-in, copyright disputes, bias or discrimination, reputational damage, lost access, or unexpected cost.
  4. What controls reduce that downside? Multi-factor authentication, least-privilege access, backups, written editorial review, privacy settings, data-minimization rules, source verification, contracts, and an exit or export plan.
  5. What evidence would make me change my mind? Independent testing, known security incidents, clear documentation, current privacy terms, disclosure practices, and whether the tool performs reliably on examples that resemble your actual work.

Govern, Map, Measure, Manage

NIST structures AI risk management around four connected functions — govern, map, measure, and manage — and the model scales down to a one-person operation perfectly well. You establish rules and accountability; you identify where and how a tool will be used; you evaluate its performance and its harms; then you mitigate, monitor, or discontinue it. Read the NIST overview.

Verify Before You Publish

I want to be direct about something, because it is the most practical lesson in this entire post.

I use AI assistants to gather and organize this weekly review — currently Perplexity for the news sweep, and Claude for drafting and verification. AI research tools are genuinely excellent at assembling a landscape quickly. They are also capable of producing citations that look authoritative and are subtly wrong: a real organization paired with a dead URL, a real article under a changed title, a recommendation that was accurate two years ago and has since been superseded.

So every link in this post was opened and checked before publication, not merely pasted. That exercise surfaced several things worth passing along:

  • The two commercial “best newsletter” roundups I consulted are useful, but both have a commercial interest. One is published by a company that ranks its own newsletter first on its own list. The other is a lead-generation site with an affiliate disclosure. Neither fact makes their recommendations wrong — it makes them a starting point rather than a verdict.
  • Several descriptions that circulate about these newsletters are out of date. SANS NewsBites publishes twice a week, not weekly. Risky Business is now two titles — Risky Bulletin three times weekly, and Seriously Risky Business weekly. Bruce Schneier’s Crypto-Gram is the monthly email; Schneier on Security is the blog it draws from.
  • NIST has flagged that its AI Risk Management Framework is being revised, which anyone quoting the 2023 version should know.

If you take one operational habit from this post, take this one: never publish a link you have not opened. It costs seconds. Publishing a broken or misattributed source costs credibility, and credibility is the entire currency of climate communication.

A Practical Hardening Checklist

If you run a site, a newsletter, or an online community, these are the measures that deliver the most protection for the least effort:

  • Turn on multi-factor authentication everywhere that offers it — domain registrar and hosting first, because whoever controls those controls everything else. Prefer an authenticator app or a passkey over SMS codes.
  • Save your recovery codes offline — MFA locks attackers out, and it will lock you out too if you lose your phone without them.
  • Use a password manager with a unique password per service. Reused passwords are how one unrelated breach becomes your breach.
  • Keep backups you have actually restored from — an untested backup is a hope, not a plan. Keep at least one copy disconnected from the live system.
  • Audit administrator accounts and plugins quarterly — remove former collaborators, deactivate and delete unused plugins, and give contributors the lowest role that lets them work.
  • Set up email authentication — SPF, DKIM, and DMARC make it substantially harder for anyone to send mail that appears to come from your domain. Most hosts will configure these on request.
  • Watch the vulnerabilities that are actually being exploited rather than every CVE ever published. CISA maintains the authoritative catalog and you can subscribe to updates: Known Exploited Vulnerabilities Catalog.
  • Check whether your addresses appear in known breaches at haveibeenpwned.com, and rotate anything that shows up.
  • Write down what you will do in the first hour of an incident — who you call, where the backups are, how you tell your members. You will not compose this calmly while it is happening.

The Reading Stack: Ten Cybersecurity Newsletters

A well-informed but manageable reading stack mixes fast daily briefs, rigorous analysis, technical research, policy coverage, and independent reporting. Every link below was verified in September 2026.

NewsletterWhy it earns a place in your inbox
Krebs on Security https://krebsonsecurity.com/ Investigations · 1–2× weekly · FreeBrian Krebs has published independently since 2009 after a decade at The Washington Post. His reporting on ransomware crews, botnets, identity theft, and payment fraud regularly runs ahead of mainstream outlets and goes several layers deeper. Read it to understand how and why, not just what.
SANS NewsBites https://www.sans.org/newsletters/newsbites/ Curated analysis · Twice weekly · FreeA high-signal roundup of consequential vulnerabilities, attacks, and policy actions, each annotated with commentary from SANS instructors and practitioners. That editorial layer is what makes it genuinely useful for decisions rather than awareness.
CyberWire Daily Briefing https://thecyberwire.com/newsletters/daily-briefing Daily brief · Weekdays · FreeA disciplined weekday digest from N2K Networks covering incidents, threat actors, government action, malware, and industry news. This is your dependable “what happened today” layer, tightly scoped enough to read quickly.
Risky Business https://risky.biz/newsletters/ Strategy & geopolitics · 4× weekly · FreeTwo titles: Risky Bulletin by Catalin Cimpanu, fast and technically grounded, three times weekly; and Seriously Risky Business by Tom Uren, weekly, for considered policy and intelligence analysis. Few newsletters treat state-sponsored activity with comparable analytical weight.
The Record https://therecord.media/ Threat intel & global events · FreeEditorially independent newsroom owned by Recorded Future, covering ransomware, espionage, critical infrastructure, and government cybersecurity. Sign up for the free CyberDaily email. Strong for a public-interest and geopolitical lens.
tl;dr sec https://tldrsec.com/ AppSec, cloud, AI security · Weekly · FreeClint Gibler’s curation of security tools, conference talks, and research, readable in roughly seven minutes. Recent issues lean heavily into AI security — prompt injection, agent attack surfaces, LLM vulnerability hunting — which makes it increasingly relevant beyond AppSec engineers.
Crypto-Gram https://www.schneier.com/crypto-gram/ Policy & privacy · Monthly · FreeBruce Schneier’s monthly compilation, running since 1998, drawn from his blog at schneier.com. Essential for reasoning about security beyond gadgets and CVEs: incentives, surveillance, regulation, and social consequences. The most valuable item on this list for a climate-policy audience.
CISA Alerts & Advisories https://www.cisa.gov/news-events/cybersecurity-advisories Authoritative U.S. guidance · As issued · FreeGovernment-issued alerts, exploited-vulnerability warnings, and concrete mitigations. Less newsletter than operational feed — which is exactly what you want when something urgent affects software you actually run.
BleepingComputer https://www.bleepingcomputer.com/ Practical incident news · Daily · FreeRapid, accessible coverage of ransomware, browser flaws, Windows and Linux issues, breaches, and scams, usually with remediation steps attached. The most immediately actionable of the daily sources for a small operator.
Unsupervised Learning https://danielmiessler.com/newsletter AI × security × policy · Weekly · FreeDaniel Miessler connects cybersecurity with AI, geopolitics, privacy, and technology strategy, with a practitioner’s perspective and an argument rather than a summary. A strong fit for cross-disciplinary readers.

The Reading Stack: Ten AI Newsletters

NewsletterWhy it earns a place in your inbox
The Batch https://www.deeplearning.ai/the-batch/ Research framing · Weekly · FreePublished by Andrew Ng’s DeepLearning.AI, pairing curated research summaries with Ng’s recurring letters. Measured and educational — a useful corrective to hype cycles, and one of the best ways to follow what matters without drowning.
Import AI https://importai.substack.com/ Policy & frontier research · Weekly · FreeWritten since 2016 by Jack Clark, a co-founder of Anthropic — worth knowing, since the author has a stake in the industry he analyzes. Even so, nothing else combines this level of technical literacy with policy and geopolitical depth. Each issue closes with AI-themed short fiction.
The Algorithm https://forms.technologyreview.com/newsletters/ai-demystified-the-algorithm/ Journalism & society · Weekly · FreeMIT Technology Review’s AI newsletter, backed by an actual newsroom: investigations, interviews, and accountability reporting on how AI affects work, power, surveillance, democracy, and public institutions. The full articles may require a subscription.
AI Snake Oil https://www.aisnakeoil.com/ Evidence-based skepticism · FreePrinceton’s Arvind Narayanan and Sayash Kapoor, authors of the book of the same name. The essential counterweight to marketing claims, particularly around prediction, automation, fairness, and deployment. If you explain AI to a general audience, this is the one that keeps you honest.
The Rundown AI https://www.therundown.ai/ Daily scan · Daily · FreeThe largest dedicated AI newsletter, with over two million subscribers, distilling the day’s model releases, launches, and research into about five minutes. Use it for speed — and verify consequential claims against primary sources.
One Useful Thing https://www.oneusefulthing.org/ AI adoption · A few times monthly · FreeWharton professor Ethan Mollick writes experiment-driven essays on using frontier models in real workflows. Closer to your situation than most: it is about adoption, education, and organizations rather than model internals. Added to the original list and worth the slot.
Ben’s Bites https://www.bensbites.com/ Tools & products · Several times weeklyBen Tossell’s builder-focused digest, blending hands-on tool tests and mini-tutorials with company deep dives. Useful for a working digital publisher deciding what is worth trying this month.
Last Week in AI https://lastweekin.ai/ Comprehensive roundup · Weekly · FreeOrganized sections for tools, research, policy, and business, paired with a long-running podcast. The right choice if you would rather skip the dailies and make one thorough weekly pass.
The Neuron https://www.theneurondaily.com/ Accessible daily · Daily · FreePlain language, humor, and practical tool recommendations. It covers the same launches as the other big dailies; the voice is the differentiator, and for many readers it is simply the one they do not skip.
TheSequence https://thesequence.substack.com/ Technical ML · FreemiumFor a more technical perspective on machine learning, model architecture, and enterprise AI. The free Sunday digest is the sensible entry point; the deeper editions are paid. Pair with Data Elixir (dataelixir.com) if you want the wider data-science ecosystem.

A Note on Rankings

Two published roundups informed this list — The CTO Club on cybersecurity and DataCamp on AI. Both are worth reading and both carry commercial incentives, as noted earlier. I have kept the selections that survived independent checking, adjusted the descriptions that had drifted out of date, and added One Useful Thing on my own judgment. Treat any “best of” list, including this one, as a place to start rather than a conclusion.

A Practical Subscription Strategy

Do not subscribe to all twenty at once. Start with a core stack of eight and adjust after two to four weeks:

  • Cybersecurity daily: CyberWire Daily Briefing
  • Cybersecurity depth: Krebs on Security
  • Cybersecurity action: CISA Alerts and Advisories
  • Cybersecurity strategy: Crypto-Gram or Risky Business
  • AI daily: The Rundown AI or The Neuron — pick one, since they cover the same stories
  • AI depth: The Batch
  • AI policy and society: Import AI and The Algorithm
  • AI skepticism: AI Snake Oil

That combination gives you breaking events, technical reality, public policy, civil-society implications, and warranted skepticism. Five lenses, eight emails, and no illusion that any single source sees the whole picture.

Keeping Inbox Overload Under Control

Create three labels or folders and route everything into them:

  • Daily scan: CyberWire, The Rundown, BleepingComputer
  • Weekly depth: Krebs, SANS NewsBites, The Batch, Import AI, The Algorithm
  • Technical reference: CISA, tl;dr sec, Data Elixir, Last Week in AI

Skim the daily digests for ten to fifteen minutes, then reserve one weekly session — mine is Sunday — for the deeper pieces. The discipline matters more than the volume. Information consumption should not displace the work of turning findings into community posts, member discussions, and actual security improvements.

Why This Supports the Mission

For a climate-education and community platform, informed technology choices are not a side concern. They are part of the work itself.

  • They protect the trust of readers, members, collaborators, and subscribers — the thing that takes years to build and an afternoon to lose.
  • They help us communicate climate information accurately rather than amplify AI-generated errors or fabricated citations, at a moment when climate misinformation is already abundant and increasingly automated.
  • They let us use AI efficiently for lower-risk work — outlines, brainstorming, transcription, metadata, draft editing, accessibility support, idea generation — while keeping human accountability for every educational claim.
  • They reduce the chance that one compromised account, malicious plugin, deceptive email, or careless AI workflow disrupts years of community-building.
  • They strengthen our ability to explain technology’s environmental, democratic, privacy, labor, and equity implications with nuance rather than hype — including the energy and water demands of AI infrastructure itself, which belongs squarely in a climate conversation.

The goal is not to become an expert on every vulnerability or every new model. Nobody can. The goal is to develop a dependable filter: verify important claims, protect sensitive data, understand tradeoffs, and make deliberate choices before the tools make them for you.

That is adaptive resiliency applied to our own infrastructure. We ask communities to prepare rather than react, to build capacity before the crisis rather than during it, and to make decisions from understanding rather than alarm. The same discipline belongs in how we run our own systems.

A note on method: I use artificial intelligence to enhance my creativity and thinking — to research, organize, draft, and pressure-test ideas. The judgment, the selections, the framing, and the responsibility for what appears here remain mine. Every source linked in this post was opened and verified before publication, which is precisely the standard this post argues for.

Que Humanidad / Compiled & Mr. Alvarez’s Thoughts | AI Enhanced.

Leave a comment

Blog at WordPress.com.

Up ↑

empowerment & inner transformation...

__________________________________

Bryan Parras

An experienced organizer and campaign strategist with over two decades working at the intersection of environmental justice, frontline leadership, and movement building. Focused on advancing environmental justice and building collective power for communities impacted by pollution and extraction. Skilled in strategic organizing, coalition building, and leadership development, managing teams, and designing grassroots campaigns. Excels at communicating complex issues, inspiring action, and promoting collaboration for equitable, resilient movements.

NJTODAY.NEWS

Your neighborhood in print since 1822

Global Justice Ecology Project

Global Justice Ecology Project (GJEP) explores and exposes the intertwined root causes of social injustice, ecological destruction, and economic domination.

WP Tavern

WordPress News — Free as in Beer.

Raw Soul Food Lifestyle by Sistahintheraw

African, Caribbean & Asian Inspired Flavours for a Raw & Living Plant-Based Food Lifestyle

mydandelionmind.wordpress.com/

Going off on tangents since 2015

Cloak Unfurled

Life is a journey. Let us meet at the intersection and share a story.

alltherawthings

...happily, naturally active...

SGI-UK Bristol, Buddhism

Nichiren Buddhism in Bristol, Nichiren Buddhists in Bristol, Soka Gakkai in Bristol

Zero Creativity Learnings

In Design and Arts

Life is an exhibition

Sarah Rose de Villiers

indigolotusnavigators

Just another WordPress.com site

DER KAMERAD

Για του Χριστού την Πίστη την Αγία και της Πατρίδος την Ελευθερία...!

Auroras Blog

Personal blog about the topics business, marketing, Wordpress, the Internet, and life in general.

The Journey of A Soul

A blog by Chad Lindsey

LWC

is one with unbounded love