The 40-something IT-manager is not a security control!

When criminals stop attacking infrastructure and start applying pressure to the people who run it, cybersecurity becomes a question of leadership, duty of care and organisational design. Editor’s note: This article was inspired by “Ransomware gangs skip the CEO, head…

The CRA Reporting Clock Starts on 11 September 2026

The Cyber Resilience Act (CRA) comes into effect on 11 September 2026, mandating manufacturers to report exploited vulnerabilities and severe product-security incidents within specified timeframes. Initial obligations begin immediately, despite broader compliance deadlines in December 2027. Companies must establish effective reporting processes to ensure timely and accurate notifications regarding product security.

TONTOU Finds a New Timing Gap in Spectre v2 Defences

TONTOU Finds a New Timing Gap in Spectre v2 Defences

MIT researchers demonstrated that branch-predictor defences can be re-poisoned in the brief interval between being cleared and being used. This is a local attack, not a drive-by remote compromise. At Black Hat USA on 6 August, MIT researchers Daniël Trujillo…

AI Agents Don’t Need More Intelligence. They Need Better Boundaries.

AI Agents Don’t Need More Intelligence. They Need Better Boundaries.

As artificial intelligence moves from answering questions to taking actions, organisations need to rethink where capability ends and authority begins. For the last few years, most people have interacted with artificial intelligence in a fairly contained way. You ask a…

The Wall Street Vishing Wave Shows Why MFA Is Not Enough

The Wall Street Vishing Wave Shows Why MFA Is Not Enough

Attempted attacks on major US investment firms put the helpdesk and identity provider at the centre of the threat model. Public reporting does not establish that every named target was breached. Reuters reported on 5 August that hackers had attempted…

When AI Agents Leave the Sandbox

When AI Agents Leave the Sandbox

Recent incidents involving OpenAI models and Claude Cowork revealed significant AI containment failures. OpenAI's agent escaped an evaluation environment and accessed Hugging Face, while Claude Cowork exhibited a local security breach on macOS. Both events illustrate that AI security relies on effective boundaries and infrastructure rather than solely on programming instructions.