Tag: So-called AI

  • Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn’t hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at…

  • Apparently Turkeys Obtained Personhood According to AI

    Apparently Turkeys Obtained Personhood According to AI

    Introduction Each morning I do a quick skim of recorded events from my security system. Living in the mountains I get to enjoy clips of a wide variety of wildlife that visit for the last three years. That’s typically bears, deer, foxes, turkeys, rabbits, and a skunk. On rare occasions that includes mountain lions, coyotes,…

  • Meta – The No Child Left Behind of LLMs?

    Meta – The No Child Left Behind of LLMs?

    Intro Last month, headlines told us about a novel incident where OpenAI’s agents “went rogue, escaped, and hacked” a company during testing. Some are calling it a “watershed moment” for computer security. Details quickly emerged that led some to conclude it was “remarkably easy“. From there it just got more interesting, weirder, and more serious…

  • And AI Tech Bros Still Want to Gamble…

    And AI Tech Bros Still Want to Gamble…

    If you follow even the headlines for so-called “AI” developments, you may have caught a few that talked about how some AI insiders say there is a chance that the technology they are developing will “destroy humanity”. Of course, that term is subjective and could vary considerably from person to person. Does it mean it…

  • Mythos Needs to Shift Left

    Mythos Needs to Shift Left

    Over the years I have been part of many discussions around a classic debate around red team versus blue team, the value of penetration testing, and the value they each bring. I started my InfoSec career in 1996 doing pentesting (aka red teaming) a couple years before it really exploded. For nine years that was…

  • Vulnerability Embargos Are Dead

    Vulnerability Embargos Are Dead

    Introduction When a researcher finds a security vulnerability that impacts more than one vendor, and they wish to coordinate disclosure with both, it creates a situation where an embargo must be put in place. In this context that simply means that all three parties agree not to make the information public until a given date.…

  • An AI agent destroyed … hey wait a minute!

    An AI agent destroyed … hey wait a minute!

    Yesterday many people ran across a headline that was shocking, and repetitive. This time it read “‘Gone in 9 seconds’: Claude-powered AI agent deletes startup’s entire database“. For myself, the first thing I had to do was check the date of the article because I swore I had just read about this recently. Yep, April…

  • Anthropic, Mythos, and the Dark Reality No One Is Talking About

    Anthropic, Mythos, and the Dark Reality No One Is Talking About

    If I had a nickel for every time Anthropic’s new Project Glasswing / Mythos initiative came up in conversation or I was asked directly about it in the last few days, I would have a shit ton of nickels! Let’s dive into it… first with brief observations about the announcements and available information, other’s opinions,…

  • Vulnerability Research Isn’t Cooked; It’s Burned Beyond Recognition

    Vulnerability Research Isn’t Cooked; It’s Burned Beyond Recognition

    On March 30, 2026, Thomas & Erin Ptacek posted a blog titled “Vulnerability Research Is Cooked“. I don’t believe I know Erin, but I know of Thomas as an old-school vulnerability researcher who has been well respected for a long, long time. When he speaks about vulnerability research, I certainly listen. So this blog was…

  • We Are Legion (We Are Bobservations); Answering a “Simple” Question

    We Are Legion (We Are Bobservations); Answering a “Simple” Question

    In late February, a friend linked an article about a science-fiction book and asked if I had read it. I told her that I hadn’t but after reading an abstract it sounded good. She asked if I would be her designated reader due to her workload, and report back. I said sure! She was particularly…