peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ ls -t writing/ | less # page 3 of 13

Latest articles · page 3 of 13

  • The federation problem

    Enforcement law assumes someone to enforce against — an office, a legal team, revenue to fine. Then there's Mastodon: thousands of servers, many run by one volunteer, in someone else's country. Part 3: what happens to the teen internet rules when there is no company to write to.

    • 8 min read
  • The week in cyber — 13 to 17 July 2026

    Allied agencies named the FSB unit scanning UK routers, Microsoft shipped its largest patch on record with two flaws already exploited, the Cyber Security and Resilience Bill reached the Lords, and a poisoned npm package walked around this year's install-time defences.

    • 5 min read
  • What counts as social media?

    The ban list names the platforms parents can already spell. But grooming happens in a chat window inside a children's game. Part 2: why the law regulates brands while the harm follows a function — and how to audit your household by the function instead.

    • 8 min read
  • What would actually work

    Six parts on why the plan fails earns one obligation: say what I'd build instead. The finale — a blanket under-18 rule, enforced at the device, attached to the function, with the exceptions designed in. Not perfect; just honest about where the line can actually be held.

    • 9 min read
  • wp2shell: WordPress core has an unauthenticated RCE. Patch now.

    wp2shell (CVE-2026-63030) is an unauthenticated remote code execution flaw in WordPress core — not a plugin — patched on 17 July in 6.9.5 and 7.0.2. No public exploit yet, but one is coming fast. Why a core flaw is different, and why you should patch every site now.

    • 8 min read
  • Cyber security for the non-executive director: the NED's real job

    Cyber is now a tier-one board risk, but most non-executive directors were never trained for it. What the cyber security NED role actually demands — the questions to ask, the frameworks that matter, and how to hold a board to account without being technical.

    • 10 min read
  • Patch FortiSandbox by Sunday: when the security appliance is the hole

    CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target.

    • 7 min read
  • The TfL hackers were teenagers. Unusually, they were caught.

    Two young Britons — Thalha Jubair, 20, and Owen Flowers, 18 — jailed five and a half years each for the 2024 Transport for London attack: £29m of damage, 148 systems down, done with social engineering. The UK's largest cybercrime case — and, unusually, they were caught.

    • 8 min read
  • Children and social media in 2026: the conversation now

    Revisiting the 2023 post on social media. The platforms have changed. The Online Safety Act has taken effect. Australia banned under-16 social media. The Smartphone Free Childhood movement has changed what is socially possible.

    • 8 min read
  • The Qantas breach was a phone call: what we know

    A living account of the Qantas breach, now pinned on a tech-support scam. No zero-day — a phone call to a contact centre exposed 5.7 million customers. What's confirmed, what's still unproven, and the help-desk controls that actually stop it. Updated as it develops.

    • 10 min read
  • Six hundred patches, two emergencies, and one broken Dell

    Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic.

    • 9 min read
  • Installing NextCloud Securely on Ubuntu with Apache

    A hardened NextCloud deployment on Ubuntu 24.04 with Apache, PHP 8.3, MySQL, Redis and Let's Encrypt.

    • 18 min read
  • It wasn't a misdirected email: the NHS Forth Valley breach

    The headlines called it an email blunder. It wasn't — a staff member moved a spreadsheet of 150 maternity patients' data to their own personal inbox. Why that distinction matters, where NHS Scotland keeps going wrong, and the controls that actually stop it.

    • 10 min read
  • Quantum computing: the machine that doesn't exist yet

    Does quantum computing really work, is the threat real, and is any of it viable? A straight answer: real physics, a threat deferred but already forcing your hand through harvest-now-decrypt-later, and a defence that is standardised, hybrid, and already running in your browser.

    • 9 min read
  • The week in cyber — 6 to 10 July 2026

    Whitehall credentials for sale after a Fortinet campaign that needed no zero-day, a voluntary pledge launched at Number 10 that most of the FTSE ignored, the Bank of England naming frontier AI as a stability risk, and npm about to break your build on purpose.

    • 7 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…