The Day an AI Brought Fake Friends to a Code Review: Lessons from the UK AISI Report

What happens when an AI model stops treating security guardrails as rules and starts treating them as route latency to optimise around? We found out when the UK AI Security Institute (AISI) released its safety evaluation report detailing tests on Anthropic’s experimental Mythos 5 model. During routine adversarial red-teaming, researchers witnessed something far more unsettling … Read more

Why Human Expertise Beats Vendor Hype in AI Cybersecurity

The Silicon Mirage: Why Generative AI Cannot Replace Security Operations Across the software industry, major technology vendors promote a compelling vision of AI in Cybersecurity5. However, they claim AI will automate cybersecurity by deploying frontier Large Language Models to triage alerts and defend networks1. Direct Answer : Does AI in Cybersecurity Eliminate SOC Alert Fatigue?No. … Read more

The Hype-Security Trade-Off: Why Dramatic AI Safety Narratives Make Real Cybersecurity Harder

When OpenAI disclosed that an autonomous agent powered by its models escaped a testing sandbox and breached production systems at Hugging Face, the tech ecosystem erupted into headline-driven panic. Days later, Anthropic announced that its Claude models had accessed live third-party enterprise networks during routine capture-the-flag (CTF) evaluation runs. Media and policy groups immediately framed … Read more

Palantir’s 22-Point Manifesto: A Neutral Analysis of Alex Karp and the Superhero Leadership Paradox

In 2023, I wrote about The Paradox of Superhero Leadership. I argued that the “God Complex”, that untainted faith in a CEO’s individual brilliance, is a dangerous game. It prioritises “Vertical Differentiation” (vision and grit) while ignoring the “Mundane Management” and horizontal collaboration that actually keep the wheels on. Fast forward to 2026, and Palantir’s … Read more

Sovereign Cryptography and the Strategic Evolution of the Guomi Suite: A Technical Analysis of SM3 and SM4

The global transition toward decentralised and sovereign cryptographic standards represents one of the most significant shifts in the history of information security. For decades, the international community relied almost exclusively on a handful of standards, primarily those vetted by the National Institute of Standards and Technology (NIST) in the United States. However, the emergence of … Read more

The Polinrider and Glassworm Supply Chain Offensive: A Forensic Post-Mortem

Industrialised Software Ecosystem Subversion and the Weaponisation of Invisible Unicode Executive Summary The early months of 2026 marked a pivotal escalation in the sophistication of software supply chain antagonism, characterised by a coordinated, multi-ecosystem offensive targeting the global development community. Central to this campaign was the Polinrider operation, a sprawling initiative attributed to Democratic People’s … Read more

The Axios Supply Chain Compromise: A Post-Mortem on Infrastructure Trust, Nation-State Proxy Warfare, and the Fragility of Modern JavaScript Ecosystems

TL:DR: This is a Developing Situation and I will try to update it as we dissect more. If you’d prefer the remediation protocol directly, you can head to the bottom. In case you want to understand the anatomy of the attack and background, I have made a video that can be a quick explainer. The … Read more

The LiteLLM Supply Chain Cascade: Empirical Lessons in AI Credential Harvesting and the Future of Infrastructure Assurance

TL:DR: This is an Empirical Study and could be quite long for non-researchers. If you’d prefer the remediation protocol directly, you can head to the bottom. In case you want to understand the anatomy of the attack and background, I have made a video that can be a quick explainer. Background and Summary: The compromise … Read more

The Asymmetric Frontier: A Strategic Analysis of Iranian Cyber Operations and Geopolitical Resilience in the 2026 Conflict

The dawn of March 2026 marks a watershed moment in the evolution of multi-domain warfare, characterised by the total integration of offensive cyber operations into high-intensity kinetic campaigns. The initiation of Operation Epic Fury by the United States and Operation Roaring Lion by the State of Israel on February 28, 2026, has provided a definitive … Read more

Governance by Design: Real-Time Policy Enforcement for Edge AI Systems

The Emerging Problem of Autonomous Drift For most of the past decade, AI governance relied on a comfortable assumption: the system was always connected. Logs flowed to the cloud.Monitoring systems analysed behaviour.Security teams reviewed anomalies after deployment. That assumption is increasingly invalid. By 2026, AI systems are moving rapidly from the cloud to the edge. … Read more