AI: Fear it, so I can sell you the…

We are already watching the fear, uncertainty and doubt industry spin up around AI. It follows a pattern anyone who has sat through a vendor pitch will recognise: take a real, narrow signal, strip out the caveats, and inflate it until it fills a keynote slide or a board paper. The problem is not that AI carries no risk. It carries plenty. The problem is that the loudest claims are almost always the least accurate, and the people making them usually have something to sell — a model, a defence against one, or a regulatory moat.

So let’s take the three narratives I keep hearing, put them next to the evidence, and separate the kernel of truth from the theatre.

Read more “AI: Fear it, so I can sell you the cure!”

How do LLMs work?

Ok full disclosure, because you know I like to say when I’m using ‘AI’, this post is specifically mostly created by an LLM. Because it’s an interesting experiment and I don’t claim to be an ‘AI’ model creation and platform expert, so let’s see if using an LLM can help me! I was in a meeting along time ago at MS Victoria with some people (can’t imagine what types of people that would be) and we were talking about this tech, it was so long ago I can’t remember the details or anyones faces (useful that)… but the convo was really good, anyway, so what is an LLM and how does it work?

Read more “How do LLMs work?”

Mythos, isn’t magic!

I’m in a bit of a rush with this one but the TLDR; the USA senate was told:

“On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”

This isn’t really great… and you will hopefully see why!

Read more “Mythos, isn’t magic!”

The AI Threat: Same Cyber Different Day!

Whilst the world is seemingly losing it’s mind from watching too many Hollywood films and thinking that LLMs are going to turn into SKYNET or the ENTITY, the majority of cyber professionals I know are like… meh, safe shizzle we have always had, but at least we don’t have to write crappy CSS and can make tools look awesome really fast these days!

The rest of this post is created by Claude Opus 4.8, prompted by my good self analysing a bunch of data I’m working on:

Read more “The AI Threat: Same Cyber Different Day!”

When AI goes wrong…

Ok so as I’m writing this I’m currently on a temporary ban from twitter…. the reasons for this I believe are more complex than one would expect. Full disclosure, I’m assuming the ban was in part due to AI but that is an assumption… but it’s the only realistic explanation I have. You might be thinking, who cares…. but bear with me….

Read more “When AI goes wrong…”

Using AI in a positive (non scary) way

Do you ever struggle to keep up with the cyber world? Not everyone is plugged into the internet 24/7 as some people (I swear I get offline sometimes!) so keeping up to date with the cyber world can be pretty tricky! Also who has time to read everything? no one that’s who! But what about if we used an LLM to read things for us and then give us an update? Well here’s an example of this!

Read more “Using AI in a positive (non scary) way”

one step closer to Skynet?

Yesterday I ran a pentest against an RDP server, the process was ok but not amazing, I had to provide more help than I would have liked, resource consumption and the idea it should keep going…. wasn’t great. The process and output wasn’t terrible at all but it didn’t blow me away.

So today I wanted to see if Claude could take on as simple active directory lab! Now let’s be clear, there were I think one or two updates to the Claude client in that time! The Claude UI even changed look and feel! So I span up an AD lab I had made a while ago and got to work!

Read more “one step closer to Skynet?”

Summary of “The National Security Act in 2024” Report

A quick GROK

This document is the first annual report (dated December 2025) by Jonathan Hall K.C., the Independent Reviewer of State Threats Legislation, appointed in February 2024. It reviews the operation of Parts 1 and 2 of the National Security Act 2023 (NSA), which came into force on 20 December 2023, along with related border powers under Schedule 3 to the Counter-Terrorism and Border Security Act 2019. The review assesses whether the new laws effectively counter state threats (malign activities by foreign powers below the threshold of armed conflict) while avoiding excessive overreach, protecting rights, and ensuring proportionality.

Read more “Summary of “The National Security Act in 2024” Report”