Categories
Links Writing

The Vulnerability-Discovery Boom Risks Creating a Patching Crisis

Al-powered vulnerability-discovery tools may ultimately give defenders a significant advantage. For now, however, they are also exposing a more immediate problem: even the largest software vendors may be unable to remediate vulnerabilities as quickly as Al systems can uncover them.

A recent investigation by Renee Dudley details how Anthropic’s Mythos has dramatically expanded the number of vulnerabilities Microsoft must address. In April, Mythos reportedly identified 90 critical and 141 important vulnerabilities in SharePoint alone.

One of the challenges linked with LLM-enabled vulnerability discovery is triaging software patches. Software vendors have traditionally deferred lower-severity vulnerabilities to concentrate limited resources first on critical or important vulnerabilities. But Al systems can potentially help adversaries identify ways to chain several seemingly minor vulnerabilities into usable exploits. That may require vendors to rethink not only how quickly they patch, but also how they assess severity and allocate remediation resources.

Of note, previously discovered exquisite exploit chains used by nation-state adversaries have incorporated non-critical vulnerabilities to facilitate their cyber operations. It will bear watching as to whether a wider range of adversaries will be able to create similar exploit chains as LLM-powered tools are integrated into adversaries’ offensive development suites.

Categories
Photography Writing

In Memory of Om Malik

Leona Kruczkowskiego & Aleje Jerozolinskie, Warsaw, 2026

I never met Om but I’d followed his writing for decades, and his photography has long been an inspiration. I waited for many years before going on a photography workshop which is being organized in Venice: it’s Om’s images, there, that showed me what photography can do in that city. His work has pulled me across the ocean and so later this year I’ll have a chance to see Venice through my own eyes, while simultaneously being inspired by his own representation of the city.

Om has/had his own very distinctive style. I’m not him but the image at the top of this post is an homage to him, his sense of minimalism through my own approach to street photography.

Throughout the day when I was out looking to make a homage photo, tributes to him from his colleagues, friends, photographers, and readers reverberated through my mind. This photograph (and post) is my effort to remember him from during my time in Poland.

I will never have the chance to meet him in person, but I will not forget his importance to me and my own love of photography.

May his name be a blessing and reverberate amongst those he touched through his life.

Categories
Links Writing

NCSC Endorses Passkeys as Default for Authentication

As reported by The Register, the UK’s National Cyber Security Centre (NCSC) has “officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.”

The NCSC has asserted that passwords should not be used where passkeys are available. This is a major departure from past guidance provided by the British cybersecurity body.

The NCSC is one of the world’s premier cybersecurity bodies and their endorsement is a major shift to how passkeys are likely to be viewed and adopted.

Where passkeys are not available, the NCSC recommends that individuals use unique passwords and multi-factor authentication, and use a secure password manager to generate and store the unique passwords.

Categories
Links Writing

Deepfakes Are Not Just a Technology Problem

I continue to worry about the ease of producing and then disseminating deepfake imagery. Recent reporting from Wired and Indicator, as an example, noted that:

The true scale of deepfake sexual abuse taking place in schools is likely much higher. One survey by United Nations children’s agency Unicef estimates that 1.2 million children had sexual deepfakes created of them last year. One in five young people in Spain told Save the Children researchers that deepfake nudes had been created of them. Child protection group Thorn found one in eight teens know someone targeted, and in 2024, 15 percent of students surveyed by the Center for Democracy and Technology said they knew about AI-generated deepfakes linked to their school.

In South Korea and Australia, schools have given pupils the option not to have their photos in yearbooks or stopped posting images of students on their official social media accounts, citing their use for potential deepfake abuse. “Around the world, there have been cases where school images were taken from public social media pages, altered using AI, and turned into harmful deepfakes,” one school in Australia said. “Imagery will instead feature side profiles, silhouettes, backs of heads, distant group shots, creative filters, or approved stock photography.”

The ability to create deepfakes is fast, inexpensive, and increasingly possible offline using open-source models and weights. There are also innumerable online services that facilitate this activity at minimal cost

But this isn’t a ‘technology’ issue alone: the underlying intent to humiliate, denigrate, and exercise social control reflects entrenched social behaviours that cannot be addressed through technical measures alone. Notwithstanding the fact that technology is used to create deepfakes, the solution will not be found in controlling the technology nor even in criminalizing the activity (though both are likely part of a broader solution). Beyond statutory or regulatory responses, we need to invest in interventions that challenge the underlying attitudes that give rise to this behaviour in the first place.

We must recognize, call out, and work to counter the misogynistic norms and underlying attitudes that too often drive their creation. This is something that we owe to children, as well as to one another, and is especially important as we live in an era where more and more images are being made every day of each and every one of us. If we fail in doing so, however, expect to see social responses such as bars on public photography, production of yearbooks, and more as a defensive response to protect children and adults alike.

Categories
Photography Writing

Using Moriyama’s Style Without His Philosophy

(Augusta & Baldwin, Toronto, 2026)

I don’t use my Ricoh GRiiix all that much but, decided to take it with me while out with my partner and shoot in its hard contrast profile that mimics Daidō Moriyama’s style.1

He’s one of my favourite photographers; while I really like his images, it’s the philosophy underlying them that truly attracts me. His use of “are, bure, boke”, which is often translated as “grainy/rough, blurry, out-of-focus,” was, in part, an aesthetic opposition to the European photojournalism style. This style tended toward a more realist presentation of the world. What he developed wasn’t just a visual style, but a way of seeing and positioning oneself in relation to the world writ large.

I’m…not shooting with Moriyama’s philosophy. I approach image making from a different perspective that lacks his particular philosophical guidestones. And so this image is experimental, for me, but the experiment is this: what is it like to use a photographer’s so-called “style” that is really an outward (and visually manifested) expression of their values and positionally, when making one’s own images?

This isn’t an image that will do much aside from torturing a few electrons to position bits in this way or that, and only to be seen by a handful of people. But as an experiment in a way of making an image, I find it deeply uncomfortable.

My discomfort stems from this mode being available on Ricoh cameras at all. Specifically, it seems to reduce a so-called “style” — which is really a philosophy — to a selectable profile in a camera. To me, this results in a flattening of what was originally a deliberate and mindful photographic practice, with the effect of subverting or consuming a way of making images and entirely eliding the rationale that undergirds this “style” in the first place.

My perception doesn’t extend to profiles that replicate film stocks, since photographers have historically used film stocks in highly individual ways. But Moriyama’s way of making images was distinctive, and this mode feels uncomfortably close to reproducing that specificity.

I know that many people love the hard contrast mode on Ricoh cameras, and can make really beautiful images with it. But it feels uncomfortable to me, and I don’t see myself using it very often going future.


  1. This blog is developed from an earlier, and shorter, analysis of this experiment on Glass. ↩︎
Categories
Links Writing

A Pragmatic Paper on Regulatory Sandboxes

I can’t recommend the paper, “Getting Regulatory Sandboxes Right: Design and Governance Under the AI Act” highly enough.

In addition to walking through regulatory sandboxes under the EU AI Act, it also helpfully frames sandboxes not merely as tools to support innovation, but as governance instruments for managing risk, uncertainty, and fundamental rights in real-world AI deployment. In doing so, the paper draws a clear distinction between sandboxes and more general regulatory engagement mechanisms: unlike advisory or guidance-based approaches, sandboxes may involve controlled and conditional flexibility from existing regulatory requirements, but always within a structured and supervised framework.

The paper functionally summarizes both the opportunities and challenges for participants, regulators and authorities, and governments, while emphasizing that this flexibility is neither absolute nor risk-free. Participation can be suspended or terminated where “significant risks to health and safety and fundamental rights” arise and cannot be mitigated, and critically, sandbox participation does not displace existing liability regimes. Even within a sandbox, actors remain subject to civil and criminal liability where harm occurs.

The walkthrough of each major stage of sandbox activity — including pre-testing, testing, and post-testing — is particularly valuable. The authors stress that sandboxes should be understood as structured, lifecycle-based processes, with clearly defined entry, monitoring, and exit conditions. During participation, organizations may benefit from reduced or sequenced compliance obligations — for example, not being required to meet the full suite of post-market monitoring or documentation requirements that apply to commercialized AI systems. However, this flexibility is conditional, time-limited, and tied to adherence to a defined sandbox plan under regulatory supervision. Once systems are market-ready, full obligations can apply, underscoring that sandboxes are not meant as a pathway to permanent regulatory relaxation.

Importantly, the paper makes clear that sandboxes can function as places where fundamental rights protections are actively tested, validated, and enforced from the outset. This is reflected in the expectation that oversight should be calibrated to risk: higher-risk systems may require closer monitoring and longer testing periods, while lower-risk applications may justify lighter-touch oversight and shorter durations.

One concept I found particularly useful is that sandboxes can be used not only to test a participant’s system, but also to actively probe it from a regulatory perspective. For example, incorporating simulated regulatory audits during sandbox participation can help prepare participants for real-world compliance expectations.

Throughout, the paper is explicit about potential governance risks associated with regulatory sandboxes. Without transparency, sandboxes can produce opaque decision-making and confer unfair advantages, as illustrated by examples where limited public information has been provided about approved experiments. Similarly, historical precedents demonstrate how poorly designed regimes can encourage regulatory arbitrage and “race to the bottom” dynamics. The authors also caution against risks of regulatory capture and uneven access, where well-resourced actors may disproportionately benefit or informally shape regulatory expectations.

The authors also make clear that sandboxes cannot be separated from broader market and regulatory dynamics. Without strong connections to implementation ecosystems, they risk becoming isolated experiments rather than pathways to responsible deployment.

Categories
Links Writing

Why Great Leaders Never Stop Learning

A recently published podcast by Harvard Business Review focused on the importance for leaders to never stop learning. The interview with David Novak — formerly of Yum! Foods — had a range of insights but the ones that stuck with me included:

  • If your job has become rote — it may be busy but you know how to solve for all the challenges that arise — then it’s likely time to find a new challenge
  • If you’re looking for a way of inspiring yourself to improve your organization or team, ask yourself “what would be the first priorities of someone who assumed my role after I left?” And then work to address those priorities!
  • Find people in surrounding fields that are different from your own and learn from them. If another organization is doing great things learn from them and how the underlying intentions or principles guiding their success can be adapted into your own organization.

Highly recommend this episode if you’re looking for a bit of inspiration in how you can develop yourself and your professional organization.

Categories
Links

Podcast Recommendation: A Snapshot of the Contemporary Ransomware Ecosystem

For those looking to catch up on the current ransomware ecosystem, this podcast discussion with Greg Linares, Principal Threat Intelligence Analyst at Huntress, is worth a listen.

Linares shares insights into the modern ransomware landscape, including how crews increasingly operate like businesses and why groups such as Akira, Medusa, RansomHub, and Qilin continue to cause significant damage.

The discussion also touches on overlap between ransomware actors and nation-state activity, what “time to ransom” means operationally for defenders, and why techniques such as ClickFix and credential theft continue to succeed at scale.

It further examines the surge in abusing remote monitoring and management (RMM) tools, how “living-off-the-land” techniques allow operations to unfold without traditional malware, and the practical defenses smaller organizations can realistically prioritize.

You can listen online, Apple Podcasts, or other podcast directories and applications.

Categories
Links Writing

The Effects of Reduced Trust Amongst Cybercriminals

A new article on Binding Hook, by Jason R.C. Nurse and William Lyne, provides an insightful assessment of how the ransomware ecosystem is evolving.

Specifically, they note that:

  • Centralized platforms are giving way to decentralized means of exchanging information (e.g. credentials now disclosed or distributed over Telegram and not a singular website or forum)
  • There is a wider, and more dispersed, group of threat actors with the effect of enabling more flexible organizational structures
  • Fragmentation around ransomware groups and operations is not translating into fragmentation of other criminal activities (e.g., social engineering or romance scams)
  • Takedowns of centralized platforms enabling Ransomware as a Service, along with exit scams, is resulting in operators avoiding locations that depend on social trust

It’s not stated but, also, as there is a more diverse set of ransomware operators — and especially if some are less ‘professional’ than others — this may make it more challenging to assess statements they make towards victims (e.g., pay us and this all goes away). It may also make it more challenging to assess or confirm whether operators will destroy or delete data upon payment. In effect, the reduction of trust in the ransomware ‘marketplace’ may have knock-on effects that affect the valuation of ransomware operations and ability to extract payments from victims.

Categories
Links Writing

AI-Assisted Vulnerability Hunting is Here

Aisle’s recent blog, “What AI Security Research Looks Like When It Works,” does a nice job in explaining the utility of LLM-enabled security research. Properly scoped and resourced, researchers can identify serious vulnerabilities that make communities much safer after patches are applied.

However, there is a distinction between high-quality reports and slop-quality reports. Some groups, such as those operating open source projects, are seeing increasing amounts of low-quality reports that are overwhelming their ability to triage incoming reports.

Aisle highlights several emergent challenges associated with LLM-enabled security research:

  1. If vulnerability reporting increases while maintainer numbers remain flat, there is a question of whether this will cause burnout among maintainers and thus impair both security- and feature-related development.
  2. Whether the 90-day responsible disclosure window remains appropriate, or needs to be tightened, in the current era of LLM-assisted discovery. At the same time, how can or should vulnerability reports be deduplicated?
  3. Whether the ability to identify and patch vulnerabilities will ultimately favour defenders or attackers.
  4. The community’s response to a substantial shift in vulnerability discovery remains uncertain.

There are a few other considerations not taken up in Aisle’s blog:

  1. To what extent will the increased ability of attackers to find vulnerabilities shift who is identified as an ‘advanced’ threat actor? While persistence is currently still linked to resourcing to maintain operations, if serious vulnerabilities (and their chains) become more widely discoverable, what effect will this have on a broader subset of actors being able to conduct cyber operations?
  2. In what ways will the organizations producing foundational models need to build in user identity or verification functionalities or access controls to potentially restrict who can (and cannot) use the models to undertake cybersecurity research?
  3. What might occur if adversaries attempt to poison training data or model weights in order to impede specific forms of LLM-enabled cybersecurity research, either now or in the future?