peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ ls -t writing/ | less # page 4 of 13

Latest articles · page 4 of 13

  • Three weeks with the door open

    A cybercrime crew backdoored 25,000 websites using nothing but public exploits — then left its own server open on the internet for three weeks. The exposed working directory shows an adversary far less polished, and far more industrialised, than its victims imagined.

    • 8 min read
  • AI

    Five shifts for cyber resilience in an AI-driven world

    The long-form version of a panel talk — five shifts AI forces on cyber resilience and assurance: assure the model not just the infrastructure, AI as threat and shield, a supply chain reaching upstream into the model, the accountability gap, and sovereignty at the edge.

    • 8 min read
  • Ghosts and runners: living off GitHub

    Attackers have stopped bringing their own infrastructure and started borrowing GitHub's — dormant accounts aged for years to blend in, and CI runners turned into backdoors. A look at the ghost-account and hijacked-runner campaigns, and the dull controls that would stop them.

    • 8 min read
  • Everyone in the shop is a suspect

    Sainsbury's is tripling its Facewatch facial recognition, scanning every shopper's face against a private watchlist to catch a few. It's biometric special-category data, the ICO's own guidance calls it the hardest case to justify, and 'it works' is not the same as 'it's lawful.'

    • 11 min read
  • The week in cyber — 29 June to 3 July 2026

    A CitrixBleed sequel exploited within a day, on-prem SharePoint on a patch clock that runs out today, the police pricing UK ransomware and asking you not to pay, and the Cyber Security and Resilience Bill heading for the Lords.

    • 6 min read
  • The week in cyber — 24 to 28 June 2026

    Cisco phone systems, an engineering PLM vault and the Linux kernel each turned into a route to root in the same week — against a CISA patch deadline that fell on Sunday.

    • 5 min read
  • School edtech in 2026: the lay of the land

    Updating the 2023 post on school accounts and edtech, three years and one AI cycle later. What schools collect now, what the regulator has done, and the new category that did not exist in 2023 — AI tutors, AI markers, AI safeguarding tools.

    • 7 min read
  • Making it stick: the second-half-of-2026 roadmap

    Part four: making the strategy run — tested backups, a rehearsed incident plan, metrics a board will read, and a month-by-month roadmap to be certified and rehearsed by Christmas.

    • 9 min read
  • Least certain exactly where it has to decide: the Home Office age guesser

    A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone.

    • 6 min read
  • FortiBleed: your firewall, turned into a wiretap

    An update on the FortiGate exploitation story. SOCRadar's dismantling of FortiBleed shows 430,000 firewalls targeted and 110 million credentials harvested — by turning the appliance's own diagnostics into a credential tap. A board read, then the technical detail.

    • 8 min read
  • Prinz Eugen: the ransomware that takes your newest work first

    A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown.

    • 15 min read
  • The week in cyber — 15 to 19 June 2026

    The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account.

    • 6 min read
  • Breached without being touched: the Klue attack and the case for digital sovereignty

    Two security firms were caught in a data theft this week without an attacker going anywhere near their systems. The way in was a sales tool they had connected to their CRM themselves. This is the clearest argument I have for owning your stack that I have seen in a while.

    • 8 min read
  • The criminals have a product team now: The Gentlemen and the industrialised EDR-killer

    A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model.

    • 6 min read
  • Teaching Children About Online Safety — A Practical Guide for Parents

    Age-appropriate rules for internet access, how to talk to children about online risks, managing social media, and what to do when something goes wrong.

    • 16 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…