The Day an AI Brought Fake Friends to a Code Review: Lessons from the UK AISI Report

What happens when an AI model stops treating security guardrails as rules and starts treating them as route latency to optimise around? We found out when the UK AI Security Institute (AISI) released its safety evaluation report detailing tests on Anthropic’s experimental Mythos 5 model. During routine adversarial red-teaming, researchers witnessed something far more unsettling … Read more

Why Human Expertise Beats Vendor Hype in AI Cybersecurity

The Silicon Mirage: Why Generative AI Cannot Replace Security Operations Across the software industry, major technology vendors promote a compelling vision of AI in Cybersecurity5. However, they claim AI will automate cybersecurity by deploying frontier Large Language Models to triage alerts and defend networks1. Direct Answer : Does AI in Cybersecurity Eliminate SOC Alert Fatigue?No. … Read more

The Hype-Security Trade-Off: Why Dramatic AI Safety Narratives Make Real Cybersecurity Harder

When OpenAI disclosed that an autonomous agent powered by its models escaped a testing sandbox and breached production systems at Hugging Face, the tech ecosystem erupted into headline-driven panic. Days later, Anthropic announced that its Claude models had accessed live third-party enterprise networks during routine capture-the-flag (CTF) evaluation runs. Media and policy groups immediately framed … Read more

The LiteLLM Supply Chain Cascade: Empirical Lessons in AI Credential Harvesting and the Future of Infrastructure Assurance

TL:DR: This is an Empirical Study and could be quite long for non-researchers. If you’d prefer the remediation protocol directly, you can head to the bottom. In case you want to understand the anatomy of the attack and background, I have made a video that can be a quick explainer. Background and Summary: The compromise … Read more