Reconnaissance for exposure management. Why context matters in the AI era
Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!),…
Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!),…
Cookies are one of the most fundamental building blocks of the modern web, and yet they are often overlooked from a security perspective. When misconfigured,…
Here’s a more logical and less emotional way to look at what’s happening with the chaotic regulation of these AI models… It took decades/centuries to…
Welcome to the latest edition of Bug Bytes! In this month’s issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google…
I’m getting more worried, and more frustrated, about this new phase of AI disillusionment. Some of it is fair. Hundreds of billions are sloshing around…
18 kits, a 37x spike in detections, and every major AiTM vendor adding it to their platform. Device code phishing has gone from espionage-grade to…
Scaling application security and attack surface monitoring inside a single enterprise is a massive headache. In June 2026, the Department for Science, Innovation and Technology…
Here are the major changes I see coming for Cybersecurity in 2026. It becomes very clear that the primary security question for a company is…
Here are the biggest changes I see coming to AI in 2026. And when I say “verifiable,” I don’t mean “trustworthy,” which a lot of…
Fable, or something as good or better. Fable is just the temporary hotness. Now that people have tasted Fable and had it pulled away, many…
My discussion with @ZackKorman on whether Dario and Anthropic are good or bad for the world. Some quick post-debate thoughts: I think Zach is very…
I’ve been working on a better way to think and talk about AGI and ASI. I’ve thought a lot about these terms in the past,…