AI

AI: Fear it, so I can sell you the…

We are already watching the fear, uncertainty and doubt industry spin up around AI. It follows a pattern anyone who has sat through a vendor pitch will recognise: take a real, narrow signal, strip out the caveats, and inflate it until it fills a keynote slide or a board paper. The problem is not that AI carries no risk. It carries plenty. The problem is that the loudest claims are almost always the least accurate, and the people making them usually have something to sell — a model, a defence against one, or a regulatory moat.

So let’s take the three narratives I keep hearing, put them next to the evidence, and separate the kernel of truth from the theatre.

Read more “AI: Fear it, so I can sell you the cure!”
Cybercrime

Using shame to enable extortion

When we look at ‘sextortion’ and ’email based extortion’ tactics used by threat actors we see a common pattern, one that leverages shame & fear. I’ve worked with some victims of this and it’s really not nice for them, the impacts are not just financial, they are emotional and sometimes more. It’s fortunately (for me) don’t however deal with this in volume, however I wanted to highlight something, the similarities between extortion and what I would describe as ‘Security Scanning’ shame scamming. Now you might think, that’s a massive leap… but bear with me, I’ve been looking at this (CTI/OSINT) plus working with ‘victims’ for years…

I’ll be posting about some research I’ve done on DNSSEC shortly too, I’ve kind of figured this topic was over years ago, but it’s recently come back on my radar, you know sometimes ‘duty calls’. But let’s look at shame based extortion patterns for now:

Read more “Using shame to enable extortion”