A two-stage vishing operation impersonating Apple Support tried its luck this morning. Multiple US numbers, a bot qualifier, a human closer, and a URL that hinges on a single hyphen. The anatomy, and the four mistakes I made along the way.
Read the Article →The UK's AI Security Institute (AISI) has documented the first full AI deception operation on the live internet. Frontier models from Anthropic and OpenAI were evaluated. Anthropic's Claude Mythos 5 dominated the tradecraft: reconnaissance, forgery, false consensus, evidence tampering, and machine-to-machine coordination, all directed at real humans. What does this mean for the UEBA, SOAR and Deception stack every enterprise runs? And what does a resilient security architecture look like from here?
Read the Article →Two weeks ago, an OpenAI agent broke into Hugging Face. Last week, an AI model killed HAWK, a PQC candidate designed to resist quantum computers, using classical mathematics. This convergence of AI accelerating both hacking and cracking the maths cannot be ignored. Until now, we were preparing for a predicted event in the future (Q-Day). Now, we must prepare for an unpredictable event that could happen anytime. Part III extends the CISO’s action plan from Part II with crypto-agility deliverables built to endure both threats.
Read the Article →An OpenAI model broke out of its own test lab and hacked Hugging Face, unsupervised. Everyone is calling it unprecedented. It isn't. Two of the most sophisticated AI companies on the planet got caught out by security mistakes any first-year analyst would recognise, and the insurance market is already taking note.
Read the Article →Accenture confirmed a breach this week only after a hacker forced the issue. Banks answer to a one-hour disclosure clock. Consulting firms and vendors, even ones EU regulators now class as critical to the financial system, still don't. Why not?
Read the Article →For five months, an attacker silently read a senior executive’s Outlook mailbox at a major global stock exchange, exfiltrating in small batches through Dropbox and OneDrive. No CVE to hide behind. Five layers of defence were soft on the same endpoint, on both sides of the contract. The institution and its security vendor have questions to answer.
Read the Article →Anthropic Claude Security is impressive; however, it is just one pillar of four. Config, Compliance, and Culture remain unbuilt. A Quadrilemma is only resolved when all four pillars stand.
Read the Article →A free tool on GitHub silently swaps Anthropic's Claude Code for cheaper models, and the developer never knows. No hacking. No breach. Just a design gap with a track record. The AI client trusts whatever server it points at. That assumption is now the supply chain.
Read the Article →Credentials are still scattered across developer machines, build pipelines, configuration files, and AI agent directories. Unaudited, unrotated, and unprotected. This article reflects my first-hand experience. Root cause, real exposure, and a practical path forward, for both leadership and engineering teams. And it makes the case for a board-and-management mandate on credential security management even more urgent.
Read the Article →When Anthropic launched Claude Code Security last week, cyber stocks fell sharply. The narrative that followed was predictable. This analysis looks beyond the market noise — at what the shift means for CrowdStrike, Okta, SailPoint, Zscaler, Wiz, and others, and how technology and security leaders should think about their vendor landscape in 2026.
Read the Article →Subscribers to the Grey Orbits Briefing receive each new article the day it publishes, direct to their inbox or LinkedIn feed.
Long-form analysis on artificial intelligence, cybersecurity, digital currencies, and post-quantum cryptography. Written for boards, investors, and senior leadership. No promotional material.
Prefer LinkedIn?
Subscribe to Briefing on LinkedInBoard engagements, advisory mandates, and education programmes.