Blog

AI

Machine Speed

I have been both watching/listening and in meetings where I have heard some ‘interesting’ statements about ‘machine speed’ hacking by with unlimited capacity and unlimited speed….

You can, if you know me, imagine my expression on my face, however I figured let’s not settle for ‘Trust me bro it doesn’t work like that’, let’s do some SCIENCE!

(I know everyone loves scientists these days after they pluck numbers out of their ass and say things like: there is a 10-70% chance AI will destroy humanity in the next 5 years’ (and have zero evidence for the math let alone evidence for the risk model other than ‘trust me, I’m super smart’).

I’m not that smart so I do actual testing of theories, and then I share things, I know, I’d make a terrible ‘scientist’. It’s hot in the lab today so this will be a quite a brief view but should contain the key details.

Read more “Machine Speed” →
AI

Getting less wrong about computing

The last two weeks online have been like a flood, I’m not even sure what words to use to describe them accurately, but I’ll give this a go:

  • Disinformation
  • Misinformation
  • Hype

I have been shocked really at what has occurred, in front of me:

  • Mass hysteria
  • Media hosting people constantly who are making unprovable claims with seemingly no real challenge

It’s been frankly exhausting to watch, let alone being involved in a range of discussions online:

  • I’ve seen people actually say things like: we have created a new lifeform, AI is alive etc. (paraphrasing)
  • I’ve had people tell me that these computing systems are not computers (WTF)
  • I’ve seen journalists essentially platform and parroting people with what appears to be significant loss of grasp of science and reality.

So I’ve been quite active online (whilst trying to field off questions from friends, family and colleagues about: is AI going to kill us? (good god how much time has been wasted!) but also I’ve been trying to give people a view of reality TODAY! So that’s partly what this blog is about!

Read more “Getting less wrong about computing” →
Leadership

Anything you can do, we can do worse!

‘On July 21, OpenAI disclosed that several of their models had broken out of an isolated test environment by exploiting a previously unknown (“zero-day”) vulnerability.’

But wait, it appears if one AI LAB having terrible security practices isn’t enough, we have another one now saying, after the Open AI incident, they have actually reviewed their logs, and they are terrible at security too!

Read more “Anything you can do, we can do worse!” →
Leadership

Vulnerabilities found with AI, oh my!

Ok, so the world is currently obsessed with AI (at least the digital world…) and with the latest Apple update releases we can see that LLMs have been used to help people find bugs! This is great news, finding bugs is better than not finding them!

The funny thing however is the obsession with CVE counts…. this is, honestly not a very useful metric to a defending org.. and I’ll try and explain why!

Read more “Vulnerabilities found with AI, oh my!” →
Strategy

From TimThumb to wp2shell: 25 Years of WordPress Mass…

TL;DR: wp2shell (CVE-2026-63030 chained with CVE-2026-60137) matters because it is a core, pre-authentication RCE reachable on a stock, plugin-free install. That is the rare category. In 25 years, unauthenticated code execution against a bare WordPress install has happened only a handful of times. The overwhelming majority of WordPress mass compromise has ridden the plugin and theme supply chain and infrastructure abuse, not core. This post maps the history so you can see where wp2shell actually sits.

Read more “From TimThumb to wp2shell: 25 Years of WordPress Mass Exploitation” →