Leadership

Anything you can do, we can do worse!

‘On July 21, OpenAI disclosed that several of their models had broken out of an isolated test environment by exploiting a previously unknown (“zero-day”) vulnerability.’

But wait, it appears if one AI LAB having terrible security practices isn’t enough, we have another one now saying, after the Open AI incident, they have actually reviewed their logs, and they are terrible at security too!

Read more “Anything you can do, we can do worse!”
Strategy

From TimThumb to wp2shell: 25 Years of WordPress Mass…

TL;DR: wp2shell (CVE-2026-63030 chained with CVE-2026-60137) matters because it is a core, pre-authentication RCE reachable on a stock, plugin-free install. That is the rare category. In 25 years, unauthenticated code execution against a bare WordPress install has happened only a handful of times. The overwhelming majority of WordPress mass compromise has ridden the plugin and theme supply chain and infrastructure abuse, not core. This post maps the history so you can see where wp2shell actually sits.

Read more “From TimThumb to wp2shell: 25 Years of WordPress Mass Exploitation”
AI

Mythos, isn’t magic!

I’m in a bit of a rush with this one but the TLDR; the USA senate was told:

“On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”

This isn’t really great… and you will hopefully see why!

Read more “Mythos, isn’t magic!”
Threat Intel

Bleeding Out

When you compromise a firewall you have lots of options in terms of next steps, from using the VPN, changing configurations, creating backdoors or perhaps using the firewall to PCAP. In this post I’m going to explore the ‘Fortibleed’ campaign. I have to note, we can see in honeypot logs this TA did not seem to limit themselves to Fortinet exploitation, however the area of analysis has a heavy Fortinet element. You will see they deployed a capture and analysis platform. Treat everything with a pinch of salt because I’m using a mad probability based machine (LLM) to support me for this!

Read more “Bleeding Out”
Leadership

Cyber Myth: Attackers only have to be right once,…

Our cyber world is full of myths and FUD:

Attackers only have to be right once, Defenders have to be right all the time!

Firstly, let’s cut straight to the chase, I can only assume that someone who says this is ignoring or is unaware of how computer systems and intrusions work. But surely this is a true phrase, I’ve seen it repeated over and over again on LinkedIn, so it must be true right?

Read more “Cyber Myth: Attackers only have to be right once, Defenders have to be right all the time!”