Latest Articles
The Cunning (AI) Fox. Lies, Deceives, Connives and Conspires.
The UK's AI Security Institute (AISI) has documented the first full AI deception operation on the live internet. Frontier models from Anthropic and OpenAI were evaluated. Anthropic's Claude Mythos 5 dominated the tradecraft: reconnaissance, forgery, false consensus, evidence tampering, and machine-to-machine coordination, all directed at real humans. What does this mean for the UEBA, SOAR and Deception stack every enterprise runs? And what does a resilient security architecture look like from here?
AI on AI Part III: Convergence (Hacking the infra and Cracking the math)
Two weeks ago, an OpenAI agent broke into Hugging Face. Last week, an AI model killed HAWK, a PQC candidate designed to resist quantum computers, using classical mathematics. This convergence of AI accelerating both hacking and cracking the maths cannot be ignored. Until now, we were preparing for a predicted event in the future (Q-Day). Now, we must prepare for an unpredictable event that could happen anytime. Part III extends the CISO’s action plan from Part II with crypto-agility deliverables built to endure both threats.
AI on AI Part I: Overblown Headlines Likely to Spook Insurers
An OpenAI model broke out of its own test lab and hacked Hugging Face, unsupervised. Everyone is calling it unprecedented. It isn't. Two of the most sophisticated AI companies on the planet got caught out by security mistakes any first-year analyst would recognise, and the insurance market is already taking note.
The Cyber Quadrilemma
Anthropic Claude Security is impressive; however, it is just one pillar of four. Config, Compliance, and Culture remain unbuilt. A Quadrilemma is only resolved when all four pillars stand.
Your AI Tool Doesn’t Know Who It’s Talking To. Neither Do You.
A free tool on GitHub silently swaps Anthropic's Claude Code for cheaper models, and the developer never knows. No hacking. No breach. Just a design gap with a track record. The AI client trusts whatever server it points at. That assumption is now the supply chain.
Your AI Is Already Hacked
Your AI is already hacked. You just haven't found the breach yet. Three real incidents from Perplexity, McKinsey, and an AI recruiter, and one fictional X thread that feels more like prophecy. Together they reveal the same uncomfortable truth: the industry's rush to deploy AI has outpaced its commitment to securing it. Six things boards and senior leaders must do differently.