peter bassill · operator
home
$ grep -l "category: opinion" articles/*.txt

Opinion.

Opinion 64 articles
2026·07·18 What would actually work Six parts on why the plan fails earns one obligation: say what I'd build instead. The finale — a blanket under-18 rule, enforced at the device, attached to the function, with the exceptions designed in. Not perfect; just honest about where the line can actually be held. 9 min 2026·07·18 wp2shell: WordPress core has an unauthenticated RCE. Patch now. wp2shell (CVE-2026-63030) is an unauthenticated remote code execution flaw in WordPress core — not a plugin — patched on 17 July in 6.9.5 and 7.0.2. No public exploit yet, but one is coming fast. Why a core flaw is different, and why you should patch every site now. 8 min 2026·07·17 Patch FortiSandbox by Sunday: when the security appliance is the hole CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target. 7 min 2026·07·17 The TfL hackers were teenagers. Unusually, they were caught. Two young Britons — Thalha Jubair, 20, and Owen Flowers, 18 — jailed five and a half years each for the 2024 Transport for London attack: £29m of damage, 148 systems down, done with social engineering. The UK's largest cybercrime case — and, unusually, they were caught. 8 min 2026·07·16 The Qantas breach was a phone call: what we know A living account of the Qantas breach, now pinned on a tech-support scam. No zero-day — a phone call to a contact centre exposed 5.7 million customers. What's confirmed, what's still unproven, and the help-desk controls that actually stop it. Updated as it develops. 10 min 2026·07·15 Six hundred patches, two emergencies, and one broken Dell Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic. 9 min 2026·07·11 It wasn't a misdirected email: the NHS Forth Valley breach The headlines called it an email blunder. It wasn't — a staff member moved a spreadsheet of 150 maternity patients' data to their own personal inbox. Why that distinction matters, where NHS Scotland keeps going wrong, and the controls that actually stop it. 10 min 2026·07·11 Quantum computing: the machine that doesn't exist yet Does quantum computing really work, is the threat real, and is any of it viable? A straight answer: real physics, a threat deferred but already forcing your hand through harvest-now-decrypt-later, and a defence that is standardised, hybrid, and already running in your browser. 9 min 2026·07·11 The week in cyber — 6 to 10 July 2026 Whitehall credentials for sale after a Fortinet campaign that needed no zero-day, a voluntary pledge launched at Number 10 that most of the FTSE ignored, the Bank of England naming frontier AI as a stability risk, and npm about to break your build on purpose. 7 min 2026·07·11 Three weeks with the door open A cybercrime crew backdoored 25,000 websites using nothing but public exploits — then left its own server open on the internet for three weeks. The exposed working directory shows an adversary far less polished, and far more industrialised, than its victims imagined. 8 min 2026·07·09 Five shifts for cyber resilience in an AI-driven world The long-form version of a panel talk — five shifts AI forces on cyber resilience and assurance: assure the model not just the infrastructure, AI as threat and shield, a supply chain reaching upstream into the model, the accountability gap, and sovereignty at the edge. 8 min 2026·07·09 Ghosts and runners: living off GitHub Attackers have stopped bringing their own infrastructure and started borrowing GitHub's — dormant accounts aged for years to blend in, and CI runners turned into backdoors. A look at the ghost-account and hijacked-runner campaigns, and the dull controls that would stop them. 8 min 2026·07·06 Everyone in the shop is a suspect Sainsbury's is tripling its Facewatch facial recognition, scanning every shopper's face against a private watchlist to catch a few. It's biometric special-category data, the ICO's own guidance calls it the hardest case to justify, and 'it works' is not the same as 'it's lawful.' 11 min 2026·07·04 The week in cyber — 29 June to 3 July 2026 A CitrixBleed sequel exploited within a day, on-prem SharePoint on a patch clock that runs out today, the police pricing UK ransomware and asking you not to pay, and the Cyber Security and Resilience Bill heading for the Lords. 6 min 2026·06·29 The week in cyber — 24 to 28 June 2026 Cisco phone systems, an engineering PLM vault and the Linux kernel each turned into a route to root in the same week — against a CISA patch deadline that fell on Sunday. 5 min 2026·06·23 Making it stick: the second-half-of-2026 roadmap Part four: making the strategy run — tested backups, a rehearsed incident plan, metrics a board will read, and a month-by-month roadmap to be certified and rehearsed by Christmas. 9 min 2026·06·21 Least certain exactly where it has to decide: the Home Office age guesser A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone. 6 min 2026·06·20 FortiBleed: your firewall, turned into a wiretap An update on the FortiGate exploitation story. SOCRadar's dismantling of FortiBleed shows 430,000 firewalls targeted and 110 million credentials harvested — by turning the appliance's own diagnostics into a credential tap. A board read, then the technical detail. 8 min 2026·06·20 Prinz Eugen: the ransomware that takes your newest work first A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown. 15 min 2026·06·20 The week in cyber — 15 to 19 June 2026 The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account. 6 min 2026·06·19 Breached without being touched: the Klue attack and the case for digital sovereignty Two security firms were caught in a data theft this week without an attacker going anywhere near their systems. The way in was a sales tool they had connected to their CRM themselves. This is the clearest argument I have for owning your stack that I have seen in a while. 8 min 2026·06·19 The criminals have a product team now: The Gentlemen and the industrialised EDR-killer A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model. 6 min 2026·06·17 Teaching Children About Online Safety — A Practical Guide for Parents Age-appropriate rules for internet access, how to talk to children about online risks, managing social media, and what to do when something goes wrong. 16 min 2026·06·16 From self-assessment to assurance: Cyber Essentials Plus and ISO 27001 Part three: turning a self-assessment into assurance. What Cyber Essentials Plus actually tests on your real machines, and how to build a proportionate ISO 27001 management system that keeps the controls alive. 8 min 2026·06·13 The week in cyber — 8 to 12 June 2026 Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other. 6 min
← prev
1 2 3
next →

full archive  ·  threats · ai · policy · defence · privacy