The First AI-Run Ransomware Attack Is Here. What It Actually Means.
Researchers documented JadePuffer, the first known ransomware attack run end to end by an AI agent. What it actually demonstrates, and what it does not.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
115 posts
Researchers documented JadePuffer, the first known ransomware attack run end to end by an AI agent. What it actually demonstrates, and what it does not.
Read the post →Every supplier you onboard makes their security part of yours. Five questions to ask before handing over a login, an integration, or a copy of your data.
Read the post →Someone walks past every firewall you own because a colleague held the door. Why physical security still decides breaches, and how testing exposes it.
Read the post →A video call from your boss authorising an urgent payment, except it is not her. A plain guide to deepfakes and the process changes that defeat them.
Read the post →Your staff already use AI tools you have not approved, exactly as they once used Dropbox. What is genuinely at risk, and why blocking it does not work.
Read the post →Public WiFi is safer than it used to be, and the network is no longer the main risk when you travel. What to set up before you go, and what to avoid.
Read the post →Most breaches are not clever. They come through an unpatched update, an unlocked screen, or an unencrypted disk. Three boring controls that do the work.
Read the post →Test, receive a report, fix the criticals, file the PDF, repeat next year. Why that cycle stopped being good enough, and what retesting should look like.
Read the post →If 95% of your estate is a priority and 32% of it is tested, you do not have a program, you have a bet. Where the gap comes from and how it widens.
Read the post →The annual penetration test satisfied compliance and reassured boards for a decade. The numbers now say that model has been overtaken. What replaces it.
Read the post →