AI Just Dethroned Stolen Passwords as the Number One Way Hackers Break In

Let me tell you about AI Just Dethroned Stolen Passwords and why it matters right now. Something just happened in cybersecurity that should make every CISO in Australia sit up and pay attention. For the first time in the history of Verizon’s annual Data Breach Investigations Report, vulnerability exploitation has overtaken stolen credentials as the number one way attackers break into organisations.

And it’s not a small shift. The 2026 DBIR, released this week, reviewed over 31,000 incidents and found that 31% of all breaches now start with vulnerability exploitation. Stolen credentials, which held the top spot for years, have been pushed into second place. The reason? Artificial intelligence.

AI Is Shrinking Your Patching Window to Hours

Here’s what should really worry you. Verizon says AI is accelerating the time to exploit known vulnerabilities, shrinking the window for defence from months to mere hours. That means the patch you deployed last Tuesday might already be too late. Attackers are using AI to scan for unpatched systems, identify the most valuable targets, and craft custom exploits at machine speed.

This isn’t theoretical. The report found that AI is being used at every stage of the attack chain, from initial reconnaissance to malware development. Threat actors are automating the boring parts of hacking, which means they can spend more time on the creative, damaging stuff.

Shadow AI Is Your Biggest Insider Threat

There’s a twist in this report that should terrify anyone running a business. Shadow AI, the use of unauthorized AI tools by employees, is now the third most common non-malicious insider action in data loss incidents.

Think about that for a second. Your marketing team is feeding customer data into unapproved AI tools. Your developers are pasting source code into free coding assistants. Your finance people are uploading spreadsheets to AI analysis tools. Every single one of those actions is a potential breach waiting to happen.

The Verizon report specifically calls out employees submitting source code and structured data via images and other formats. They don’t even realise they’re creating a vulnerability.

The Numbers Don’t Lie

Let’s put some hard numbers on this. CrowdStrike reported earlier in 2025 that AI-enabled adversaries increased their attacks by 89% year-over-year. Combine that with Verizon’s finding that AI is automating attack techniques at scale, and you’ve got a threat landscape that looks nothing like it did two years ago.

Verizon’s Chief Information Security Officer Nasrin Rezai put it bluntly: “We need to fight AI with AI. We need to incorporate them into our practices at a scale that we have never done before.” That’s not marketing speak. That’s a warning.

The Mythos Question

Here’s something the report doesn’t cover, but probably should. Verizon’s DBIR data doesn’t include the impact of Anthropic’s Mythos model, which has raised serious cybersecurity concerns due to its advanced coding and vulnerability-identification capabilities. Verizon is part of a controlled initiative called “Project Glasswing” that allows select organisations to use Mythos for defensive purposes. But the offensive capabilities are already out there.

What You Need to Do Right Now

Stop thinking about cybersecurity as a patching problem. It’s now an AI problem. Here’s where to start:

Audit your Shadow AI usage. You need to know exactly which AI tools your team is using, authorized or not. If you don’t have an AI governance policy, write one this week. Not next month. This week.

Cut your patching cycle to days, not weeks. If your mean time to patch is measured in weeks, you’re already behind. AI-powered attackers will find and exploit your unpatched systems before your next maintenance window.

Deploy AI-powered detection. If you’re still relying on signature-based detection, you’re bringing a knife to a gunfight. You need security tools that can recognise AI-generated attacks and respond in real time.

Train your people on AI risks. Your employees don’t know they’re creating vulnerabilities. Make sure they do. Regular training on what data can and cannot go into AI tools is non-negotiable.

The gap between attackers using AI and defenders using AI is widening. The organisations that survive the next twelve months will be the ones that stop treating AI security as a future problem and start treating it as today’s emergency.

Related Reading:

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Microsoft Defender Has Two Zero-Days Being Exploited Right Now. Patch Immediately.

0

Another week, another development in the world of Microsoft Defender Has Two Zero-Days. When the agency responsible for US cyber security issues an emergency directive telling every federal agency to patch within two weeks, you pay attention.

On May 20, CISA added two Microsoft Defender zero-day vulnerabilities to their Known Exploited Vulnerabilities catalogue. Both are being actively exploited in the wild. Both have patches available. The clock is ticking.

What’s Actually Vulnerable

The first flaw, CVE-2026-41091, is a privilege escalation bug in the Microsoft Malware Protection Engine. Versions 1.1.26030.3008 and earlier are affected. If exploited, an attacker gains SYSTEM privileges on your machine. That’s the highest level of access possible on a Windows system. The root cause is an improper link resolution weakness, essentially a link following flaw that lets an attacker trick the engine into loading malicious content with elevated permissions.

The fix is straightforward: update to version 1.1.26040.8.

The second flaw, CVE-2026-45498, is a denial-of-service vulnerability in the Microsoft Defender Antimalware Platform. This affects versions 4.18.26030.3011 and earlier, which is the platform used by System Center Endpoint Protection and Security Essentials among others. An attacker can trigger a DoS state on unpatched devices, potentially disabling your defences at the worst possible moment.

Update to version 4.18.26040.7.

The CISA Mandate

CISA has invoked Binding Operational Directive 22-01, which means this isn’t a suggestion. All Federal Civilian Executive Branch agencies must secure their systems by June 3, 2026. That’s two weeks from the order date.

Their guidance is blunt: apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

For those of us outside the federal government, the message is the same. If CISA considers these vulnerabilities serious enough to mandate a two-week patch cycle across all federal agencies, you should treat them with similar urgency.

How to Check If You’re Protected

Even with automatic updates enabled, you should verify. Here’s how:

  1. Open Windows Security
  2. Go to Virus and threat protection
  3. Click Protection updates and select Check for updates
  4. Navigate to Settings > About
  5. Check the Antimalware Client Version number

Make sure your version meets or exceeds the patched versions listed above. If it doesn’t, force the update manually.

Microsoft has stated that the default configuration in their antimalware software keeps definitions and the platform up to date automatically. That’s true for most users. But “most users” isn’t the same as “all users,” and the organisations most likely to be running outdated versions are exactly the ones that can least afford a breach.

The Bigger Picture

There’s something deeply uncomfortable about vulnerabilities in your security software. You install an antivirus to protect yourself. When that same software becomes the attack vector, it undermines the entire trust model.

These aren’t theoretical risks. CISA says both vulnerabilities are being actively exploited. That means someone, somewhere, is using these flaws against real targets right now.

The privilege escalation bug is particularly concerning. Gaining SYSTEM-level access through your security software gives an attacker everything they need to install persistent backdoors, exfiltrate data, or move laterally across your network. However, they’d be doing it through a process that’s trusted by default by every security tool on your system.

What You Should Do

  • Check your version now. Don’t assume automatic updates have you covered.
  • Force an update if your version is behind.
  • Notify your IT team if you’re in an enterprise environment.
  • Monitor your logs for unusual activity from the Defender process.
  • Consider the timeline. If these are being exploited now and patches are available, the window between disclosure and mass exploitation is shrinking fast.

Microsoft’s Defender team does solid work under enormous pressure. But when the product designed to catch threats becomes one, the entire industry needs to take notice.

Patch now. Check your version. Don’t be the organisation that gets caught waiting.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Cloudflare Just Taught an AI to Chain Security Bugs Into Real Exploits

I keep coming back to Cloudflare Just Taught an AI because it affects every part of digital life. I’ve spent years watching AI vendors promise that their models will revolutionise cyber security. Most of the time, the reality falls short. Finding bugs is one thing. Proving they matter is another.

Cloudflare just showed me something different.

They partnered with Anthropic on Project Glasswing, pitting a new security-focused language model called Mythos Preview against their own codebase of over 50 repositories. The results are worth paying attention to.

The Big Leap: Exploit Chain Construction

Previous frontier models could find individual vulnerabilities. They’d spot a use-after-free bug, flag a buffer overflow, report a logic error. But they couldn’t connect the dots. They’d hand you a list of low-severity findings and call it a day.

Mythos Preview does something different. It takes those same low-severity bugs, the ones that would normally sit invisible in a backlog for months, and chains them into a single, working exploit. It can turn a memory corruption bug into full system control through return-oriented programming chains. It writes proof-of-concept code, compiles it, runs it, and iterates until it has working proof or a confirmed dead end.

“What changed with Mythos Preview is that a model can now take those low-severity bugs and chain them into a single, more severe exploit.”

Cloudflare described the model’s reasoning as resembling “the work of a senior researcher.” That’s not marketing fluff. When a model can independently construct exploit chains, it’s operating at a level we haven’t seen before.

The Harness: How to Scale AI Security Research

Here’s where it gets practical. Cloudflare didn’t just throw the model at their code and hope for the best. They built a staged pipeline, what they call a harness, to leverage Mythos Preview’s strengths while managing its weaknesses.

The key lessons:

  • Narrow scope beats broad prompts. Telling an AI “find all the bugs” is useless. Telling it “examine this specific function for trust boundary violations” produces results.
  • Ask separate questions. “Is this code buggy?” and “Can an attacker actually reach this bug?” are fundamentally different questions. The model performs better when you split them.
  • Run parallel narrow tasks. Instead of one agent trying to cover everything, run 50 focused hunters simultaneously, then deduplicate findings.
  • Use adversarial review. A second agent with different prompts catches the noise the first one generates.

The pipeline runs through recon, hunting, validation, gap-filling, deduplication, reachability tracing, and structured reporting. It’s methodical. It’s boring. It works.

The Refusal Problem

One finding that caught my attention: Mythos Preview exhibits organic refusals on certain security requests, but they’re inconsistent. Same task, different framing, opposite results. Sometimes it’ll help with an exploit chain. Sometimes it won’t.

This matters because it tells us that model guardrails built into the weights alone aren’t reliable. If you’re building security tools on top of these models, you need additional safeguards. The model’s own judgement about what it should and shouldn’t help with is too unpredictable for production use.

The Signal-to-Noise Challenge

False positives remain the biggest headache in AI-assisted vulnerability research. Memory-unsafe languages like C and C++ generate more false positives than memory-safe languages like Rust. Models tend to over-report hedged findings, words like “possibly” and “potentially.”

Mythos Preview improves on this. It produces clearer reproduction steps and working proofs, which reduces the triage burden on human researchers. When the model can prove a bug exists by triggering it, you don’t waste time debating whether the finding is real.

Why This Matters for the Rest of Us

Cloudflare is one of the few companies with the resources and expertise to do this kind of research properly. The fact that they’re sharing their approach publicly is significant.

The implications are straightforward:

  • If AI can chain low-severity bugs into critical exploits, your attack surface just got bigger. Bugs that were “low priority” yesterday are tomorrow’s incident.
  • Generic coding agents won’t cut it for security work. The context mismatch between “write features” and “find vulnerabilities” is too large.
  • The organisations that benefit most will be the ones that build proper harnesses, not the ones that just point a model at their code and hope.

Cloudflare also flagged a dual-use concern. The same capabilities that let an AI defend your code can be turned against someone else’s. There’s no sugar-coating that reality.

My Take

I’ve been sceptical of AI-powered security tools for a while. Most of what I’ve seen is glorified static analysis with a chatbot wrapper. Project Glasswing is different. It demonstrates genuine reasoning about vulnerability exploitation, not just pattern matching.

The staged harness approach is the real takeaway here. AI security research isn’t about finding a magic model. It’s about building the right infrastructure around a capable model. Narrow tasks, parallel execution, adversarial review, and structured reporting. Boring engineering, not flashy demos.

For security teams watching this space: start thinking about how you’d build a harness for your own codebase. The models are getting capable enough that the bottleneck is shifting from “can AI find bugs?” to “can we operationalise the findings?”

Cloudflare plans to share more about how these architectural principles protect their customers. I’ll be watching.

Related Reading

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

AI Just Broke the 19-Year Record. Here’s What It Means for Your Business.

AI-powered cybersecurity attack concept with digital shield cracking under pressure

Few topics in technology right now are as important as AI Just Broke the 19-Year. I’ve been writing about cybersecurity for years, and every time Verizon drops its annual Data Breach Investigations Report, I sit up and pay attention. This year’s report, released yesterday, contains a finding that should make every business owner in Australia stop what they’re doing and listen.

For the first time in the report’s 19-year history, software vulnerabilities have overtaken stolen credentials as the number one way attackers get into your systems. However, AI is the reason why.

The Numbers That Should Scare You

The 2026 DBIR analyzed over 31,000 security incidents and 22,000 confirmed breaches across 145 countries. The headline finding: vulnerability exploitation was the initial attack method in 31% of all breaches. That’s a massive shift. For nearly two decades, stolen passwords and credentials were the top way in. Not anymore.

Here’s why. AI has compressed the time between discovering a vulnerability and weaponizing it from months to just hours. What used to require a team of skilled researchers now takes a single attacker with a large language model and a few spare hours. The economics have fundamentally changed.

As Trey Ford from Bugcrowd put it: “The DBIR’s 19-year credential streak ending is not primarily a credential story. It is an economics story. AI is making vulnerability discovery and weaponization so fast and cheap that attackers no longer need a stolen password.”

Shadow AI: Your Biggest Internal Threat

But here’s the part that really got me. The report found that employee use of unapproved AI tools tripled in just one year, from 15% to 45% of the workforce. That means nearly half your staff are uploading company data, source code, and confidential information to external AI models you don’t control.

This isn’t a hypothetical risk. This is happening right now, in your organisation, whether you know it or not. Every time someone pastes a client email into ChatGPT, or uploads a spreadsheet to an AI tool without IT approval, they’re creating a data exposure risk that traditional security tools can’t see.

The report calls this “shadow AI” and it represents what experts are calling a massive internal coverage gap that most enterprises remain completely blind to.

The Patching Problem Is Getting Worse

The volume of vulnerabilities is exploding. Security researchers found 48,000+ vulnerabilities last year, an 18% increase. The dataset grew from 68.7 million records in 2022 to 527.3 million in 2025. That’s an eightfold increase in just three years.

And organisations are falling further behind. Only 26% of critical vulnerabilities were fully remediated in 2025, down from 38% the year before. The average time to patch critical vulnerabilities increased to 43 days, up from 32. Even the best-performing organisations can only patch 30-40% of critical vulnerabilities in the first week.

What You Should Do Right Now

Here’s my practical advice, based on what the report recommends:

First, audit your shadow AI usage. You need to know what AI tools your team is using. Run a network audit, check browser histories, and have the conversation with your staff. This isn’t about banning AI, it’s about understanding your exposure.

Second, prioritise patching based on active exploitation, not severity scores alone. The report shows that the probability of exploitation drops after 30 days, 90 days, and about 9 months. If something is being actively exploited in the wild, patch it today, regardless of what CVSS score it has.

Third, invest in automated vulnerability management. The human bottleneck is real. You need tools that can detect, contextualise, prioritise, and remediate without waiting for a human to approve every step. As one expert put it, the defenders who close the gap will be the ones who use AI agentially, not as a co-pilot, but as autonomous workflows.

Fourth, review your supply chain. Supply chain attacks surged 60%, with vendor vulnerabilities now accounting for 48% of all breaches. Every third-party tool, every SaaS platform, every cloud service is a potential entry point.

The Bigger Picture

What strikes me about this report is how it confirms what I’ve been saying for months. AI is a double-edged sword. It’s making us more productive, but it’s also making attackers faster, cheaper, and more effective. The organisations that will survive are the ones that stop treating cybersecurity as an IT problem and start treating it as a business survival issue.

The 48% ransomware figure is also worth noting. Nearly half of all breaches now involve some form of ransomware action, up from 44% the prior year. However, 50% of ransomware breach victims showed signs of an infostealer event within 95 days of intrusion. The attack chain is getting longer and more sophisticated.

The cybersecurity landscape has fundamentally shifted. AI hasn’t just changed the tools attackers use, it’s changed the economics of attack. When vulnerability exploitation becomes cheaper and faster than stealing credentials, every unpatched system becomes a sitting duck. The question isn’t whether you’ll be targeted, it’s whether you’ll be ready.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

80% of Organisations Are Worried About AI Data Leaks. Most Aren’t Doing Anything About It.

If you care about 80% of Organisations Are Worried, this is the story you need to read today. Something’s gone wrong with how we’re handling AI security, and the numbers are staring us in the face.

I was reading through Mimecast’s State of Human Risk 2026 report this morning, and there’s a stat that stopped me cold: 80% of organisations are concerned about sensitive data leaking through generative AI tools. Eighty percent. That’s almost everyone.

Now here’s the kicker. Only 40% report being fully prepared with specific strategies for AI-driven threats. That’s a 40-point gap between knowing there’s a problem and actually doing something about it. It’s like knowing your house is on fire but only half the residents have bothered to buy a fire extinguisher.

The report surveyed 2,500 IT security and decision-makers across nine countries, and the findings are brutal. 69% of security leaders say AI-powered attacks are inevitable within the next 12 months. Yet 60% are not fully prepared. We can see the train coming, but nobody’s getting off the tracks.

When Theory Meets Reality

If you think this is just numbers on a page, consider what happened at NYC Health + Hospitals last week. The largest public healthcare system in the United States disclosed a breach affecting 1.8 million people. Hackers had access for three months, from November 2025 to February 2026, and they walked away with medical records, Social Security numbers, and here’s the scary part, fingerprints and palm prints.

Think about that for a second. You can change your password. You can cancel a credit card. But you cannot change your fingerprints. Those 1.8 million people will carry that exposure for the rest of their lives.

The breach came through a third-party vendor, which is exactly the kind of supply chain vulnerability that AI tools are making easier to exploit. When you’re rushing to deploy AI across your organisation, every integration point becomes a potential attack vector.

The AI Vulnerability Explosion

It’s not just Mimecast sounding the alarm. Cycode’s research shows that publicly reported AI security incidents increased by 56.4% from 2023 to 2024, and the trend hasn’t slowed. Their analysis of the top AI security vulnerabilities in 2026 paints a worrying picture:

  • Prompt injection remains the number one attack vector, with a critical CVE (CVSS 9.6) enabling remote code execution through hidden prompts in GitHub Copilot.
  • 81% of security teams lack visibility into how AI is used in their own codebases. You can’t protect what you can’t see.
  • 45% of AI-generated code contains vulnerabilities. That’s nearly half the code being pushed by tools developers trust.
  • Shadow AI (unauthorised AI tool usage) affects 76% of organisations and adds an average of $670,000 to breach costs.

What This Means for You

If you’re running a business, here’s what you need to do right now:

1. Inventory your AI tools. Find out what’s being used across your organisation, including the unofficial stuff. If your team is using ChatGPT on personal accounts for work tasks, that’s Shadow AI, and it’s a data leak waiting to happen.

2. Audit your AI-generated code. If your developers are using Copilot, Claude, or any AI coding assistant, you need a review process. That 45% vulnerability rate isn’t a theoretical risk, it’s a code review backlog.

3. Review your vendor access. NYC Health + Hospitals got hit through a third-party vendor. Every external tool and service that touches your systems is a potential entry point.

4. Implement least-privilege access for AI agents. If you’ve deployed AI agents (and according to Gartner, 40% of enterprise apps will have them by end of 2026), make sure they can only do what they absolutely need to do. 80% of IT workers have already witnessed unauthorised agent actions.

5. Train your people. The report found that only 28% of organisations combine security awareness training with continuous monitoring. Training alone isn’t enough. Monitoring alone isn’t enough. You need both.

The Bottom Line

We’re in a weird moment where everyone can see the problem but almost nobody is moving fast enough to fix it. AI is simultaneously the biggest security risk and the most promising security tool. The organisations that figure out how to manage that paradox are going to be fine. The rest are going to end up in next quarter’s breach statistics.

The gap between knowing you have a security problem and actually fixing it is where attackers live. Right now, that gap is 40 percentage points wide, and it’s growing. Stop reading about it and start doing something about it.


Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

A Worm Just Hacked 160+ npm Packages — And OpenAI Got Hit Too

Worm Just Hacked 160+ is one of those subjects that keeps surfacing in every security conversation. I’ve been writing about cyber security long enough to know when something is genuinely scary. This one qualifies.

Over the past week, a worm called Mini Shai-Hulud tore through the npm JavaScript ecosystem like wildfire through dry grass. It compromised over 160 packages across 373 malicious versions – including major libraries from TanStack, Mistral AI, and UiPath. However, here’s the kicker: OpenAI confirmed that two of their employee devices were compromised in the attack.

How It Actually Worked

This wasn’t some basic phishing scam. The attackers pulled off a three-stage chain that security researchers are calling the first documented case of a malicious npm package carrying valid SLSA Build Level 3 provenance. That’s a big deal – it means the malware came with a legitimate-looking “certificate of authenticity.”

Here’s the chain:

  1. Hijacked GitHub Actions workflow: The attackers created a malicious pull request (#7378) that exploited a misconfigured GitHub Actions workflow using pull_request_target. This ran attacker-controlled code inside the legitimate build.
  2. Cache poisoning: The malicious code poisoned the pnpm package store cache with a specific key, which was later consumed by the legitimate release workflow.
  3. OIDC token theft: During the release build, attacker code extracted the OIDC token directly from runner memory and used it to publish malicious packages to npm – authenticated as TanStack’s own release workflow.

Once inside, the worm self-propagated. It would hijack an infected developer’s npm profile, append a malicious postinstall script to their package.json files, and spread to every package that developer maintained. It hit TanStack’s React Router, Vue Router, Solid Router, and router-core packages. It hit Mistral AI’s client library. It hit 40+ UiPath packages. However, it kept spreading.

The Really Nasty Bits

The malware wasn’t content with just stealing credentials. It installed editor persistence hooks in both Claude Code’s settings and VS Code’s task files. Every time a developer opened their editor, the malware would re-execute. It also installed a system service – on Linux via systemd, on macOS via LaunchAgents – that polled GitHub with the stolen token.

And then there was the dead-man’s switch: if the stolen GitHub token was revoked, the malware would run rm -rf ~/ and destroy the developer’s entire home directory. Let that sink in. You detect the malware, you try to do the right thing by revoking the token, and your machine nukes itself.

Stolen data was exfiltrated via the Session/Oxen P2P network and GitHub GraphQL API “dead-drop” commits – techniques designed to blend into normal traffic and evade detection.

What OpenAI Did

OpenAI published a detailed response confirming that two employee devices were compromised. They found no evidence that user data, production systems, or intellectual property were affected. But they rotated code-signing certificates across all platforms as a precaution.

The practical impact? Every macOS user needs to update their OpenAI apps by June 12, 2026 – ChatGPT Desktop, Codex, and Atlas. After that date, macOS will block apps signed with the old certificate. The last affected versions are ChatGPT Desktop 1.2026.125 and Codex 26.506.31421.

What You Need to Do Right Now

If your team uses any TanStack packages – and if you’re building React apps, there’s a good chance you do – here’s the priority list:

1. Check for compromise:

find node_modules/@tanstack -name "router_init.js" -exec shasum -a 256 {} \;

The compromised hash is ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c.

2. Kill the dead-man’s switch immediately. Before you rotate anything, disable the persistence mechanisms. Remove the editor hooks. Remove any injected GitHub Actions workflows.

3. Rotate secrets in this order: npm tokens, GitHub PATs, AWS credentials, HashiCorp Vault tokens, Kubernetes service account tokens, SSH keys, and Claude Code session logs.

4. Block these domains at DNS: *.getsession.org, api.masscan.cloud, git-tanstack.com.

5. Audit your package-lock files for any of the 169 affected package names. The full list is in the Snyk advisory and Aikido’s analysis.

The Bigger Picture

This attack exposes something fundamental about how we build software today. The entire npm ecosystem runs on trust – you trust the maintainers, you trust the CI/CD pipelines, you trust that a signed package actually means it’s safe. Mini Shai-Hulud proved that provenance is not a safety signal. A package can have valid provenance from a trusted workflow, but if that workflow was hijacked, the build was compromised.

Supply chain attacks are no longer theoretical. They’re automated, they’re self-propagating, and they’re targeting the exact libraries your developers use every single day. The tools for defending against this exist – minimum release ages, provenance validation, strict dependency pinning – but most teams haven’t deployed them yet.

Every supply chain attack teaches the same lesson: the libraries you trust are only as secure as the pipelines that build them. If you haven’t audited your CI/CD workflows for pull_request_target misconfigurations, you’re not ready for what’s coming next.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

IBM Report: AI-Generated Breaches Now Cost $5.72 Million. Here’s What Australian Organisations Need to Do

Phishing has surged 1,265%. The average AI-enabled breach now costs $5.72 million. Somewhere between the sales pitches and the fear campaigns, that 2025 IBM Cost of a Data Breach Report delivers a simple message Australian organisations should stop ignoring: adopting AI without governance is not innovation, it is a financial and operational liability.

That $5.72 million figure is 13% higher than the previous year. IBM ties the rise directly to organisations pushing AI into customer, employee, and supplier workflows without access controls, data classification, or incident response planning. The gap between AI rollout and AI oversight is not just a technical problem. Finance, risk, and legal should also care because breach costs compound across regulatory exposure, customer churn, and remediation time.

What the Numbers Actually Mean

The same reporting period showed AI-enabled cyber attacks rose 47%. Microsoft Cyber Signals tracked a 46% increase in AI-generated phishing content. DeepStrike’s tally found 82.6% of phishing emails now use AI in some form. That is not a distant threat. It is the current email threat landscape.

On the defensive side, IBM reports organisations with mature AI security tools see average breach costs $1.8 million lower than those without. The difference is not magic. It is automated threat detection, rapid containment, and endpoint visibility.

Shadow AI Is Eating Your Budget

Shadow AI is one of the most underdiscussed cost drivers. IBM found many organisations lacked AI governance frameworks, leaving employee-deployed tools operating outside security review. A finance team pasting customer data into a third-party AI assistant, or a developer connecting internal docs to an unvetted LLM, creates exposure no perimeter firewall can stop.

Trend Micro and other researchers documented thousands of unprotected AI services online, including Chroma servers and vector databases, open to anyone who knows how to query them. Once an AI tool is integrated into workflows, it is rarely decommissioned cleanly. Governance needs to start before deployment, not after a breach team arrives.

Practical Steps That Do Not Require a Budget Increase

Start with identity. Strong authentication, passkeys where possible, and a formal process for removing access when someone leaves. Then map your AI footprint. Every connected LLM, every third-party chatbot, every internal tool with access to email or files should be logged and reviewed. Third, assume breaches will include AI-powered reconnaissance and test your response accordingly. Red-teaming and tabletop exercises should include synthetic media and prompt-injection scenarios now, not next year.

The organisations controlling AI costs are not the ones waiting for perfect governance. They are the ones enforcing minimum controls before another employee signs up for the next AI du jour.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Mythos, APRA, and ASIC: Are Australian Enterprises Ready for the AI Threat?

Abstract AI neural network representing frontier model capabilities

Every time I think I have seen it all with Mythos, APRA, and ASIC, something new emerges. On April 7, Anthropic dropped Claude Mythos Preview on the world. By April 30, APRA had written a letter to every bank, insurer, and super fund in Australia telling them to get their house in order. By May 7, ASIC followed up with their own, making it clear that cyber resilience is now a licensing obligation, not a nice-to-have.

Three events. Three weeks. One message: the game has changed, and most organisations aren’t ready.

What Mythos Actually Is

Let’s not sugarcoat this. Mythos isn’t just another incremental update to Claude. Anthropic themselves call it their “most capable frontier model to date.” The system card describes a “striking leap” in benchmark scores. The NYT reported it triggered “emergency responses from central banks and intelligence agencies.”

When intelligence agencies start paying attention to an AI model, you know it’s not just another chatbot upgrade.

What makes Mythos different from its predecessors? Capability. Raw, frightening capability. The kind that can find vulnerabilities faster, craft more convincing phishing attacks, and automate attack chains that used to require skilled human operators.

What APRA Actually Said

APRA’s letter on April 30 wasn’t gentle. They’d done a deep-dive on Australia’s largest banks, insurers, and super funds. What they found was sobering.

Boards are interested in AI’s benefits but lack the technical literacy to challenge AI risks. Governance hasn’t kept pace with adoption. Identity management systems aren’t designed for AI agents. Security testing doesn’t cover AI-specific attack paths. However, perhaps most worryingly, many entities are treating AI as “just another technology.”

It’s not. AI changes the rules. APRA spelled out the attack vectors: prompt injection, data leakage, insecure integrations, exploit injection, and manipulation of autonomous AI agents. These aren’t theoretical threats. They’re happening now.

APRA explicitly called out Mythos by name. They’re “engaged across the sector on the potential for increased cyber threats from high capability AI frontier models such as Anthropic Mythos.” When a prudential regulator names a specific AI model in a letter to the entire financial sector, that’s not a suggestion. That’s a warning.

What ASIC Said a Week Later

If APRA’s letter was the warning, ASIC’s was the hammer. Commissioner Simone Constant didn’t mince words: “The clock is at a minute to midnight.”

ASIC made twelve specific demands. Reassess cyber plans. Confirm governance frameworks. Identify and protect critical assets. Strengthen fundamentals. Minimise attack surfaces. Review user access. Patch systems promptly. Implement defence-in-depth. Prepare for incident response. Manage third-party risks. Use AI defensively.

And here’s the part that should make every board sit up: cyber resilience is a core licensing obligation. Not optional. Not “when you get around to it.” Now.

ASIC even pointed to their recent win against FIIG Securities, where they secured a $2.5 million penalty for inadequate cyber controls. That’s the enforcement precedent. That’s what “stronger supervisory action” looks like in practice.

The Gap Between Awareness and Action

Here’s what worries me. Both APRA and ASIC are saying the same thing: you need to act now. But the gap between awareness and action at most organisations is enormous.

Boards are getting briefed on AI. They’re nodding along. They’re approving budgets. But are they asking the right questions? Do they understand what prompt injection actually means for their customer data? Do they know whether their AI agents have appropriate access controls? Can they answer whether their security testing covers AI-specific attack vectors?

APRA’s observation that boards are “still developing the technical literacy required to provide effective challenge on AI related risks” is polite language for: most boards don’t understand what they’re approving.

What You Should Be Doing Right Now

If you’re in a regulated entity, here’s what I’d be doing this week:

First, read both letters. Not a summary. Not the executive brief. The actual letters. APRA’s is detailed and specific. ASIC’s twelve-step list is a checklist you can hand to your CISO today.

Second, ask your security team one question: “Can you show me our AI-specific attack surface?” If they can’t answer that, you have a problem.

Third, check your identity management. APRA specifically called out that IAM capabilities “have not yet adjusted to nonhuman actors such as AI agents.” If your systems can’t distinguish between a human user and an AI agent, you’re exposed.

Fourth, look at your patching timelines. APRA noted that “implementation timelines for information security remediation activities are not consistently aligned to the accelerated threat environment.” If you’re still patching on a monthly cycle, you’re behind.

Fifth, ask about your third-party AI dependencies. Who are your AI providers? What access do they have? What happens if they get compromised? APRA and ASIC both flagged supplier concentration and opacity as major risks.

The Bigger Picture

What we’re seeing is the regulatory framework catching up with reality. For years, AI governance was theoretical. Boards talked about it. Consultants wrote reports about it. Nothing much changed.

Mythos changed that. Not because it’s malicious, but because it’s capable. When a single AI model can find vulnerabilities faster than your security team can patch them, the status quo stops working.

APRA and ASIC are telling the financial sector: the threat landscape has fundamentally shifted. Your governance, your security, your resilience – all of it needs to evolve. However, you need to do it now, not next quarter.

The question isn’t whether you’ll be affected by AI-driven threats. It’s whether you’ll be ready when they arrive.

When both your prudential regulator and your conduct regulator are sending urgent letters about the same threat in the same month, the time for discussion is over. The time for action is now.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Your Smart Home Is Watching You. Here’s How to Fight Back.

0

Let me tell you about Your Smart Home Is Watching and why it matters right now. I like my smart home. I do. Being able to check who’s at the door from my phone, adjust the thermostat without getting off the couch, and play music by asking the air – it’s genuinely convenient.

But let’s be honest about what we’ve traded for that convenience. Every one of those devices is watching, listening, and collecting data about how we live. However, most of it is going straight to the cloud.

What Your Smart Home Actually Knows

Let’s go through the usual suspects:

Smart speakers (Alexa, Google Home, Siri) – They’re listening for their wake word, but they’re also recording snippets of conversation. Amazon has admitted that human reviewers listen to some recordings. Google’s been caught storing location data even when you turn off location history.

Smart cameras and doorbells (Ring, Nest, Arlo) – They know when you come and go, who visits, when you’re home, when you’re not. Ring has partnerships with over 2,000 police departments in the US. Think about that.

Smart thermostats (Nest, Ecobee) – They know when you’re home, when you sleep, when you’re away. Combined with your schedule, that’s a pretty detailed picture of your daily life.

Smart TVs – They’re tracking what you watch, when you watch it, and how long you watch for. Some even listen to conversations in the room.

What You Can Actually Do

Start with what matters most. You don’t have to rip everything out. Focus on the devices that collect the most sensitive data – cameras, speakers, and anything with a microphone.

Check the privacy settings. Most smart devices have privacy settings buried in their apps. Disable voice recording storage where possible. Turn off “personalisation” features that require your data. Opt out of sharing with third parties.

Segment your network. Put smart devices on their own WiFi network, separate from your computers and phones. If one device gets compromised, the attacker can’t jump to your main devices.

Update everything. Outdated firmware is how most smart device attacks work. Enable automatic updates wherever possible.

Consider alternatives. For the truly paranoid (and I mean that as a compliment), open-source alternatives like Home Assistant let you control smart devices without sending data to the cloud. It takes more setup, but you keep your privacy.

The Uncomfortable Trade-Off

Here’s the honest truth: you can’t have 100% privacy and 100% convenience. Something has to give. The goal isn’t to eliminate all data collection – that’s impossible in a connected home. The goal is to make conscious choices about what you’re sharing and with whom.

Most people never check the privacy settings on their devices. That’s exactly what the manufacturers are counting on. Don’t be most people.

Convenience is great until you realise what it cost you. Check your settings today.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

AI Agents Are Everywhere. Your Security Team Probably Isn’t Ready.

Abstract representation of artificial intelligence with neural network patterns

The conversation around AI Agents Are Everywhere. Your has reached a critical point. I’ve been thinking about AI agents a lot lately. Not the chatbots that answer customer service questions – those are old news. I’m talking about autonomous agents that can browse the web, write code, access databases, and make decisions without a human in the loop.

They’re being deployed everywhere. However, most organisations have no idea what they’ve just let through the front door.

The Problem Nobody’s Talking About

Here’s the thing about AI agents: they’re essentially interns with root access. They can do amazing things, but they can also do amazing damage if something goes wrong.

Think about it. You give an AI agent access to your codebase, your customer database, your internal tools. It’s productive, sure. But what happens when someone tricks it into sharing that data? Or when it accidentally deletes something important? Or when it gets manipulated through prompt injection into doing something you never intended?

This isn’t hypothetical. Research from NTT DATA this week highlighted that enterprises are deploying AI agents faster than they can secure them. The gap between capability and security is growing, not shrinking.

What I’m Worried About

Prompt injection. Someone puts malicious instructions in a document, email, or webpage that your AI agent processes. The agent follows those instructions instead of yours. It sounds like science fiction, but it’s happening right now.

Data exfiltration. Your AI agent has access to sensitive information. A well-crafted query can trick it into sharing that information in its responses. The agent isn’t being malicious – it’s just doing what it was asked.

Shadow AI. Your marketing team signed up for an AI tool without telling IT. That tool now has access to your customer data, and nobody’s monitoring what it’s doing with it.

What You Can Do

Start with least privilege. Give AI agents only the access they need for their specific task. Not general access to everything. Not “we’ll figure it out later.” Specific access for specific tasks.

Log everything. If you can’t see what your AI agents are doing, you can’t protect against what they’re doing. Every action, every query, every response – log it.

Test for prompt injection. Red-team your AI deployments. Try to trick them. If you can do it, someone else definitely can too.

Establish governance now. Don’t wait for a breach to figure out your AI policies. Who can deploy agents? What access can they have? What happens when something goes wrong? Answer these questions before you need to.

The Window Is Closing

AI agents are getting more capable every week. The security gaps we have today are going to be the attack vectors of tomorrow. We need to close them now, while we still can.

The organisations that establish strong AI governance today will be the ones still standing when the attacks come. However, they will come.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.