Tech · Culture · Fiction
Your second factor is a phone call
SMS 2FA on PayPal is a routing decision, not a credential. The session cookie is the boundary, and attackers have already routed around the factor.
CISA flagged a 17-year-old Excel flaw
A 17 year old Excel flaw is being actively exploited and flagged by US cyber defence. Operator analysis of what failed, why, and what must change.
Engineering teams keep granting agents production database writes
AI agent vulnerabilities are systems engineering failures, not security failures. The fix is architectural containment, not better prompts or guardrails.
Lagos published guidelines, not controls
Lagos cybersecurity guidelines describe intent, not enforcement. An operator analysis of why policy without system-level controls does not stop attackers.
Pick offense or defense
Two paths into infosec - offense and defense - broken down at the mechanism level. Foundation, tooling, telemetry, and the divergence point.
The helpdesk chat window is the breach
Microsoft Teams helpdesk impersonation succeeds because identity verification is placed at the channel boundary, not at the credential action.
The power adapter was the attack
A WiFi camera concealed in a hotel power adapter transmitted to a foreign server. The boundary failed at the physical layer.
The Wire — latest
All →- BlueNoroff Weaponizes Fake Zoom Calls, Recruits Victims as Bait for Next Targets
- DOJ cites Comey's '86 47' seashell Instagram post as evidence in indictment push
- Drone pilot's lawsuit forces feds to drop no-fly zones over moving ICE vehicles
- Ex-NSA Chief Revisits Snowden Leaks: Regrets and Lessons 13 Years On
- FCC fast-tracks ABC license review after Kimmel joke about Melania Trump
- GPT-5.5 Codex System Prompt Bans Mentions of Goblins, Gremlins, and Pigeons
- Japan Airlines pilots humanoid robots for baggage handling at Haneda
- LiteLLM pre-auth SQLi flaw under active exploitation, secrets harvested
- Microsoft's VibeVoice ASR runs locally on Mac, transcribes an hour in under 9 minutes
- pip 26.1 ships lockfiles and dependency cooldowns
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.