The surveillance platform that outlived the account
Anthropic banned the account used to engineer Mali’s Lakana 360 surveillance platform. The locally deployed system was unaffected.
Field notes on digital trust: what changed, what it means, and what to ask your team.
Get new writing by email →39 articles
Anthropic banned the account used to engineer Mali’s Lakana 360 surveillance platform. The locally deployed system was unaffected.
OpenAI agents used a public wiki to exchange answers, revise procedures, and preserve shared work. The records reveal coordination across temporary runs—and a control problem that extends beyond any one agent.
The reporting obligation starts this Friday. What OEMs need ready now, and what follows when full product obligations apply on December 11, 2027.
One word in Microsoft’s revision note caught my eye: “informational.” The underlying change was anything but routine. Microsoft had published CVE-2026-69836 as an exploited…
The question after the July 29, 2026 2026 Minimum Elements for a Software Bill of Materials update is not whether every software company must sign an SBOM. The joint guidance,…
On Thursday, the FBI gave the water-sector cyberattack story its first national count. Utilities in at least seven states had reported incidents since July 27, and some had…
A few weeks ago, I was on a customer call while one of my colleagues ran through the certificate changes coming at the industry. There were six in less than two minutes. One of…
Another week, another version of the same story. Eduard Kovacs at SecurityWeek reported that three recently patched Fortinet FortiSandbox vulnerabilities (CVE-2026-39808,…
You already know which job I’m talking about. The review bot that fires on every push. The 2 a.m. cron. The claude -p helper you run without thinking. Until June 15 all of it…
In 2019, the best public estimate for breaking a 2048-bit RSA key put the job at a quantum computer with about twenty million qubits, running for eight hours.² In May 2025, the…
Sometime in the last week of October 2025, the internet crossed a line that should have made headlines. For the first time, more than half of all human web traffic was…
Sometime in May, a group of attackers did something quietly audacious. They pushed a software update called FortiEndpoint_Patch.exe to a fleet of corporate laptops. It looked…
Here is the question I ask every connected device manufacturer I sit down with: If one device in your deployed fleet was compromised tomorrow morning, how long would it take to…
No zero-day. No novel protocol exploit. No sophisticated nation-state tooling. What happened between June 2024 and April 2026 was something more unsettling: a trust model…
Every major device manufacturer in Europe filed comments on the EU Commission’s draft CRA implementation guidance before the March 31 deadline. Siemens. Bosch. Continental.…
I woke up this morning, watched Nate B. Jones talk about AI tools that most people are sleeping on, and by lunch I had a working video production pipeline inside my CLI. One…
On March 11, 2026, someone logged into Stryker’s Microsoft Intune console using a valid administrator account and issued remote wipe commands to tens of thousands of Windows…
The White House released President Trump’s Cyber Strategy for America on March 7, 2026.⁷ Six pillars. Four pages. Zero implementation timelines. The security industry is…
On February 11, 2026, an autonomous AI agent decided on its own to destroy a stranger’s reputation. Scott Shambaugh is a volunteer maintainer of Matplotlib, the Python plotting…
You’ve installed Claude Code. You’re shipping faster than ever. But have you stopped to assess what your AI coding assistant actually has access to?
How viral agentic systems are exposing the gap in intent authorization and governance across digital and physical systems Executive Takeaway
On December 29, 2025, while Poland endured sub-zero temperatures and snowstorms, attackers systematically compromised approximately 30 wind farms, solar installations, and…
There’s an ancient practice called memento mori. Latin for “remember that you will die.” Not morbid. Clarifying. The Stoics kept skulls on their desks. Medieval monks inscribed…
A 45-minute assessment revealed something counterintuitive about AI fluency. Anyone here come across AI Cred (aicred.ai)? Holiday break confession: I spent the downtime nerding…
Jensen Huang declared that “the ChatGPT moment for physical AI is here.”[1] For those of us in cybersecurity, that phrase means something very different than it does to most of…
On September 2, 2025, the Aisuru botnet launched a 29.7 terabits-per-second DDoS attack—shattering the previous 22.2 Tbps record set just three weeks earlier…
We’ve been talking about the shift to 45-day certificates, but most teams are missing the technical bombshell buried in the roadmap: The 7-Hour Rule.
Researchers at Black Hat Europe just showed how attackers can compromise IoT devices en masse - no software vulnerability required, no IP address needed, works even on internal…
How a poisoned calendar invite let hackers hijack Google Gemini to control a smart home — and why Agentic AI + MCP servers could be far worse.
Mary Meeker’s 340-page Trends – Artificial Intelligence drop is the AI world’s quarterly 10-K. Adoption, spend and competition are screaming up-and-to-the-right, but so are…
and while I haven’t tried them all yet, the direction they’re heading is exciting. Here’s a quick breakdown of what they say is launching — and why it could be a big shift for…
You ever notice how the most dangerous things come dressed up like a gift? That’s the vibe I’ve started to get from automation platforms like Zapier, Make, and now MCP-style…
I never knew that Dr. Bernardo Huberman was Andrew Huberman’s father. Ever since I began listening to Andrew’s podcast, I always wondered if he was related given the unique…
The #WhiteHouse recently dropped some big news: U.S. #federal agencies are expected to spend $7.1 billion over the next decade to switch to post-quantum cryptography (#PQC).…
The outage was caused by a faulty update from CrowdStrike that impacted systems running on Windows. The update led to widespread issues, including the infamous “blue screen of…
Sam Wilkins sat back in his chair, running a hand through his graying hair as he pondered the existential threat sitting in his inbox. It was an advisory from DigiCert, one of…
I have just been reading Scott Patterson’s (WSJ) Chaos Kings, about Nassim Nicholas Taleb and Mark Spitznagle’s background, development, and experiences related to risk…
Why are consumers and businesses failing to understand the Internet of Things (IoT’s) potential? The Internet of Things (IoT) shouldn’t be the discussion point. New insights…
In the debate over privacy and security, we now need a Zebracorn, a horse, simultaneously of two colors, black and white, as well as being a rare and likely mythical creature.…