Source of the domain task list: (ISC)² CISSP Exam Outline. [isc2.org]
Domain 2 covers the identification, classification, handling, protection, tracking, and lifecycle management of information and assets. All responsibilities revolve around ensuring that data is properly governed at every stage from creation to destruction.
2.1 Identify and Classify Information and Assets
✔ What This Means…
Coverage: 1.1–1.12 in the (ISC)² outline. [cisa.gov]
1.1 Professional Ethics
What the CISSP expects of you
(ISC)² Code of Professional Ethics requires you to: protect society and the common good; act honorably, honestly, justly, responsibly and legally; provide diligent and competent service; and advance and protect the profession. [cisa.gov]
Organizational codes of ethics (e.g., conflict…
Theme: Cybercrime / Supply Chain / AI-Driven Social Engineering / Exploited Vulnerabilities
Audience: Novice → Pro 💡 | Mode: Learn + Play 🎮
🔍 Story 1: Zendesk Ticket Systems Hijacked in Massive Global Spam Wave
What happened 🧠
Attackers abused unsecured Zendesk support ticket systems to send out huge volumes of automated spam emails from…
Focus: what happened, key technical concepts, what it looks like in real orgs, plus an XP Quest per story 🎮
1) Google Gemini + Calendar Invites → Indirect Prompt Injection + Data Exposure
What happened 🧠📅
Researchers found an indirect prompt injection path where an attacker can hide instructions inside a Google Calendar invite, and…
🔗 Sources
https://thehackernews.com/2026/01/google-gemini-prompt-injection-flaw.html
https://thehackernews.com/2026/01/security-bug-in-stealc-malware-panel.html
The Security Paradox: New Study Reveals 69 Vulnerabilities in AI-Generated Apps
VCs Invest Billions in AI Security to Combat Rogue Agents by 2026
Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections
https://www.infosecurity-magazine.com/news/malicious-google-chrome-extension/
🧠 Today’s TL;DR (What happened)
AI / Prompt Injection (Gemini + Calendar):…
MITRE ATT&CK: The Analyst’s Superpower
Imagine you’re dropped into a battlefield. You know the enemy is out there, but where do you start? MITRE ATT&CK is your map of the adversary’s playbook—every tactic, every technique, every move they might make. It’s not just theory; it’s built from real-world attacks.
Why It’s Epic
It turns chaos…
To Gamemaster Alchemy