<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Javvad Malik</title>
	<atom:link href="https://javvadmalik.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://javvadmalik.com</link>
	<description>Security &#124; Life &#124; Cynicism</description>
	<lastBuildDate>Fri, 05 Jun 2026 15:58:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>

<image>
	<url>https://javvadmalik.com/wp-content/uploads/2024/07/cropped-monogram-color.png?w=32</url>
	<title>Javvad Malik</title>
	<link>https://javvadmalik.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">84356237</site><cloud domain='javvadmalik.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<atom:link rel="search" type="application/opensearchdescription+xml" href="https://javvadmalik.com/osd.xml" title="Javvad Malik" />
	<atom:link rel='hub' href='https://javvadmalik.com/?pushpress=hub'/>
	<item>
		<title>Breach of Confidence: 05 June 2026</title>
		<link>https://javvadmalik.com/2026/06/05/breach-of-confidence-05-june-2026/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 15:58:32 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4516</guid>

					<description><![CDATA[I&#8217;ve spent the week watching people try to solve human problems with technical solutions and technical problems with human rage. Neither works as well as you&#8217;d think. Also, while I was speaking at infosec about the latest AI threats people need to be wary of, my motorbike which was in the &#8220;secure&#8221; ExCel car park &#8230; <a href="https://javvadmalik.com/2026/06/05/breach-of-confidence-05-june-2026/" class="more-link">Continue reading <span class="screen-reader-text">Breach of Confidence: 05 June&#160;2026</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png"><img width="751" height="423" data-attachment-id="4519" data-permalink="https://javvadmalik.com/2026/06/05/breach-of-confidence-05-june-2026/breach-of-confidence/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png" data-orig-size="751,423" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}" data-image-title="breach of confidence" data-image-description="" data-image-caption="" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png?w=751" src="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png?w=751" alt="" class="wp-image-4519" srcset="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png 751w, https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png?w=150 150w, https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png?w=300 300w" sizes="(max-width: 751px) 100vw, 751px" /></a></figure>



<p class="wp-block-paragraph">I&#8217;ve spent the week watching people try to solve human problems with technical solutions and technical problems with human rage. Neither works as well as you&#8217;d think. <br><br>Also, while I was speaking at infosec about the latest AI threats people need to be wary of, my motorbike which was in the &#8220;secure&#8221; ExCel car park got stolen. There&#8217;s an analogy in there somewhere. I just can&#8217;t put my finger on it. </p>



<p class="wp-block-paragraph"><strong>The Booby Trap Defence</strong></p>



<p class="wp-block-paragraph">A developer embedded code that deletes itself if touched by AI tooling. Now he&#8217;s getting threats from people who apparently believe sabotage is a legitimate development philosophy.</p>



<p class="wp-block-paragraph">The position on AI is irrelevant. I won&#8217;t lie that I kind of admire the audacity of someone thinking you can fight a culture war by rigging explosives in someone else&#8217;s repository. </p>



<p class="wp-block-paragraph"><a href="https://gizmodo.com/dev-says-hes-getting-threats-after-leaving-a-booby-trap-for-vibe-coders-2000765231">https://gizmodo.com/dev-says-hes-getting-threats-after-leaving-a-booby-trap-for-vibe-coders-2000765231</a></p>



<p class="wp-block-paragraph"><strong>The FBI Knocks Twice</strong></p>



<p class="wp-block-paragraph">A journalist got a visit from the FBI about his reporting. They wouldn&#8217;t say why. So he&#8217;s suing to find out, which is the correct response when transparency suddenly becomes a one-way mirror.</p>



<p class="wp-block-paragraph">Accountability shouldn&#8217;t stop just because you&#8217;re holding the badge.</p>



<p class="wp-block-paragraph"><a href="https://www.rcfp.org/litigation/whittaker-v-doj/">https://www.rcfp.org/litigation/whittaker-v-doj/</a></p>



<p class="wp-block-paragraph"><strong>The Pi Heist</strong></p>



<p class="wp-block-paragraph">Someone physically installed a Raspberry Pi inside a bank&#8217;s network switch. Not to exfiltrate data. To replay legitimate PIN verifications and drain ATMs remotely.</p>



<p class="wp-block-paragraph">The perimeter was never the problem. The assumption that anything inside the perimeter is trustworthy remains the gift that keeps on giving.</p>



<p class="wp-block-paragraph"><a href="https://cybersec.picussecurity.com/s/unc2891-bank-heist-explained-caketap-rootkit-and-raspberry-pi-attack-27676">https://cybersec.picussecurity.com/s/unc2891-bank-heist-explained-caketap-rootkit-and-raspberry-pi-attack-27676</a></p>



<p class="wp-block-paragraph"><strong>One Click, Full Access</strong></p>



<p class="wp-block-paragraph">GitHub&#8217;s browser-based VSCode has a webview bug that hands over a token with full read-write access to all your repos, including private ones. One click on a malicious link and the keys are copied.</p>



<p class="wp-block-paragraph"><a href="https://blog.ammaraskar.com/github-token-stealing/#why-full-disclosure">https://blog.ammaraskar.com/github-token-stealing/#why-full-disclosure</a></p>



<p class="wp-block-paragraph"><strong>The Harness Problem</strong></p>



<p class="wp-block-paragraph">Your AI agent gets all the scrutiny. The harness that actually executes its instructions gets none. It&#8217;s got more privilege than the model and you&#8217;ve probably never even looked at it.</p>



<p class="wp-block-paragraph">We&#8217;re so busy worrying about what the brain might do that we forgot to check what the hands are holding.</p>



<p class="wp-block-paragraph"><a href="https://cybersec.pillar.security/s/your-agent-harness-has-more-privilege-than-your-agent-27726">https://cybersec.pillar.security/s/your-agent-harness-has-more-privilege-than-your-agent-27726</a></p>



<p class="wp-block-paragraph"><strong>Google Goes Home</strong></p>



<p class="wp-block-paragraph">The European Parliament swapped Google for Qwant (I&#8217;m not even going to try to pronounce that), a French privacy-first search engine. It&#8217;s a lovely gesture. Whether a genuinely privacy-respecting tool can survive prolonged contact with institutional governance is a question we&#8217;ll have answered soon enough.</p>



<p class="wp-block-paragraph"><a href="https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine">https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine</a></p>



<p class="wp-block-paragraph"><strong>Even Criminals Have HR</strong></p>



<p class="wp-block-paragraph">Nova ransomware gang had to publicly fire someone for breaking rule one: don&#8217;t infect Russia or CIS countries. The apology was immediate and free. The alternative would not have been.</p>



<p class="wp-block-paragraph">Turns out even transnational cybercrime syndicates have an employee handbook and consequences for violating it. Just not the kind with a tribunal.</p>



<p class="wp-block-paragraph"><a href="https://www.theregister.com/cyber-crime/2026/06/02/dumbass-criminal-breaks-the-first-rule-of-ransomware-club/5250380">https://www.theregister.com/cyber-crime/2026/06/02/dumbass-criminal-breaks-the-first-rule-of-ransomware-club/5250380</a></p>



<p class="wp-block-paragraph"><strong>Vulnmaxxing and Vendor Lock-In</strong></p>



<p class="wp-block-paragraph">Funny how the tool that suddenly finds ten thousand bugs also sells you the only tool capable of fixing them at speed.</p>



<p class="wp-block-paragraph">The poor get poorer, just with better metrics this time.</p>



<p class="wp-block-paragraph"><a href="https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing">https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing</a></p>



<hr class="wp-block-separator has-alpha-channel-opacity" />



<p class="wp-block-paragraph">That&#8217;s your lot. If you&#8217;re still reading these on LinkedIn instead of your inbox, you can fix that. If you&#8217;ve got a story I missed or just want to tell me I&#8217;m wrong, reply to this. I read them all, even the angry ones.</p>



<p class="wp-block-paragraph">Especially the angry ones.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4516</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>

		<media:content url="https://javvadmalik.com/wp-content/uploads/2026/06/breach-of-confidence.png?w=751" medium="image" />
	</item>
		<item>
		<title>Are we hiring for the wrong thing?</title>
		<link>https://javvadmalik.com/2026/05/26/are-we-hiring-for-the-wrong-thing/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Tue, 26 May 2026 10:28:53 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4422</guid>

					<description><![CDATA[I see many job postings asking for someone who is &#8216;passionate about cybersecurity.&#8217; Enthusiastic. A team player. Positive attitude preferred. And maybe I&#8217;m being a bit click-baity here, but they&#8217;re hiring for the wrong thing entirely. The person you actually want exhibits the following: Optimism, in security, is a liability. Not because optimists are bad &#8230; <a href="https://javvadmalik.com/2026/05/26/are-we-hiring-for-the-wrong-thing/" class="more-link">Continue reading <span class="screen-reader-text">Are we hiring for the wrong&#160;thing?</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I see many job postings asking for someone who is &#8216;passionate about cybersecurity.&#8217; Enthusiastic. A team player. Positive attitude preferred.</p>



<p class="wp-block-paragraph">And maybe I&#8217;m being a bit click-baity here, but they&#8217;re hiring for the wrong thing entirely.</p>



<p class="wp-block-paragraph">The person you actually want exhibits the following:</p>



<ul class="wp-block-list">
<li> Upon receiving a beautifully wrapped gift, immediately wonders who sent it and why. </li>



<li>Who reads a terms and conditions update and assumes something has quietly gotten worse. </li>



<li>Who looks at a system that has been running fine for three years and thinks: that&#8217;s suspicious.</li>
</ul>



<p class="wp-block-paragraph">Optimism, in security, is a liability. Not because optimists are bad people, but because optimism requires believing things will probably be fine. Security requires believing, with some conviction, that things probably won&#8217;t be.</p>



<p class="wp-block-paragraph">Most threat modellers I&#8217;ve met are usually not fun at dinner parties. They have already considered four ways the evening could go wrong before the starter arrives. They are not catastrophising&#8230; it&#8217;s just how they&#8217;re wired. </p>



<p class="wp-block-paragraph">The industry keeps mistaking cheerfulness for competence and then wondering why its detection rates are poor. A happy person sees a login at 2am from an unusual IP and thinks: probably fine, someone working late. The other kind sees the same alert and starts pulling logs.</p>



<p class="wp-block-paragraph">Passion fades. Suspicion is structural.</p>



<p class="wp-block-paragraph">Hire accordingly.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4422</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybersecurity films that need to be made</title>
		<link>https://javvadmalik.com/2026/05/25/cybersecurity-films-that-need-to-be-made/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Mon, 25 May 2026 16:17:50 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/2026/05/25/cybersecurity-films-that-need-to-be-made/</guid>

					<description><![CDATA[The film industry is running out of ideas. I know this because they have made 10 (20?) films about a group of people who drive cars aggressively (sometimes into space) and called it a franchise. Meanwhile, the entire cybersecurity industry is sitting here, completely unrepresented, absolutely bursting with the raw material of cinematic gold. Allow &#8230; <a href="https://javvadmalik.com/2026/05/25/cybersecurity-films-that-need-to-be-made/" class="more-link">Continue reading <span class="screen-reader-text">Cybersecurity films that need to be&#160;made</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><br>The film industry is running out of ideas. I know this because they have made 10 (20?) films about a group of people who drive cars aggressively (sometimes into space) and called it a franchise. </p>



<p class="wp-block-paragraph">Meanwhile, the entire cybersecurity industry is sitting here, completely unrepresented, absolutely bursting with the raw material of cinematic gold.<br><br>Allow me to pitch.<br><br><strong>Beverly Hills CISO</strong><br><br>A scrappy security analyst from a small regional SOC stumbles onto something in the logs he absolutely should not have found. His manager suspends him. His manager&#8217;s manager suspends him harder. He is told in no uncertain terms to take some time off and think about his attitude.<br><br>He does not take time off. He drives to headquarters, badgers the help desk, sweet-talks his way into the server room, and solves the entire incident using a visitor badge, a packet capture tool, and the kind of confidence that only comes from having nothing left to lose.<br><br>The villain is the VP of Finance.<br><br>It is always the VP of Finance.<br><br><strong>Lethal CISO</strong><br><br>An ageing CISO who has been in the industry since passwords were optional and firewalls were a suggestion. His new deputy is twenty-six, has never worn a tie, and once gave a board presentation entirely in emoji. Together they are investigating a ransomware gang that turns out to be operating out of a co-working space in East London.<br><br>The old one wants to follow procedure. The young one wants to post about it on LinkedIn while it is happening.<br><br>Somehow, between the two of them, they get there.<br><br>The tagline writes itself: &#8220;One is too old for this. One is too online for this. Together they are slightly above average.&#8221;<br><br><strong>Die Hard with a Patch Cycle</strong><br><br>It is Christmas Eve. A lone sysadmin is the only person left in the office, voluntarily, because he is finally going to get through the vulnerability backlog that has been sitting at 4,000 items since April.<br><br>Then the building gets compromised. Not physically. Digitally. By a group of criminals who have decided that a financial services company with a skeleton crew and a sysadmin in a Christmas jumper is the perfect target.<br><br>He has no budget. He has no team. He has twelve years of suppressed frustration and a terminal window.<br><br>Yippee-ki-yay, patch this! (Doesnt quite roll off the tongue)<br><br><strong>Top Gun: Maverick SOC</strong><br><br>A legendary penetration tester, the best who ever lived, was pushed out of the industry years ago for being too reckless, too brilliant, and too unwilling to write up his findings in the approved report template.<br><br>He is called back for one final engagement. The target is unhackable, apparently. The timeline is impossible. The junior red teamers assigned to him are cocky, technically gifted, and have absolutely no idea what they are walking into.<br><br>He does not follow the methodology. He never follows the methodology.<br><br>He gets the finding.<br><br><strong>F1: The CISO</strong><br><br>He had one bad incident. One. A breach that was not entirely his fault, that happened during a period of significant organisational dysfunction, during which the board had ignored seventeen of his recommendations and the budget had been cut three times in eight months.<br><br>But the industry has a long memory and a short attention span for context.<br><br>He is brought in to defend a startup that nobody believes in, against a threat actor that everyone is afraid of. The odds are terrible. The infrastructure is embarrassing. His laptop has a sticker on it that says &#8220;I Survived a PCI Audit&#8221; and it is not ironic.<br><br>He is not here to be liked. He is here to prove that he has still got it.<br><br>He has still got it.<br><br><strong>Predator: Zero-Day</strong><br><br>A highly trained red team is sent into a client environment for a routine engagement. One by one, something starts taking them out. Not the client&#8217;s defences. Something else. Something that got there first.<br><br>The last one standing realises, with dawning horror, that they are not the apex threat actor in this network.<br><br>They are the second best.<br><br></p>



<p class="wp-block-paragraph"><br><br>Hollywood, my inbox is open. The industry has the stories. It just needs someone to write the treatment.<br><br>I am available.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4501</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Alex Honnold and Other Keynote Choices</title>
		<link>https://javvadmalik.com/2026/05/25/alex-honnold-and-other-keynote-choices/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Mon, 25 May 2026 09:21:00 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4442</guid>

					<description><![CDATA[KB4con 2026 had Alex Honnold as a keynote speaker. He&#8217;s someone who climbs extremely tall mountains with no ropes and no safety equipment. Just him, the rock, and a Wil-e-coyote style ending if anything goes slightly wrong. I have sat through a lot of conference keynotes. Former heads of state explaining that leadership is important. &#8230; <a href="https://javvadmalik.com/2026/05/25/alex-honnold-and-other-keynote-choices/" class="more-link">Continue reading <span class="screen-reader-text">Alex Honnold and Other Keynote&#160;Choices</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">KB4con 2026 had <a href="https://en.wikipedia.org/wiki/Alex_Honnold">Alex Honnold</a> as a keynote speaker. He&#8217;s someone who climbs extremely tall mountains with no ropes and no safety equipment. Just him, the rock, and a Wil-e-coyote style ending if anything goes slightly wrong.</p>



<p class="wp-block-paragraph">I have sat through a lot of conference keynotes. Former heads of state explaining that leadership is important. Astronauts confirming that space is large. Digital fortune tellers telling a room full of security professionals that the future will be different from the past.</p>



<p class="wp-block-paragraph">A man who has made a careful, considered, expertise-backed decision to remove every single safety net is a genuinely interesting choice for a security conference. Not because the metaphor writes itself. Because it got me thinking about what safety measures are actually for.</p>



<p class="wp-block-paragraph">Some controls exist because the risk is real and the mitigation works. Some controls exist because removing them would look bad in the post-incident report. The free soloist has thought, with more rigour than most, about which category each piece of protection falls into. He has not abandoned caution. He has replaced generic caution with extremely specific, deeply informed caution. Before climbing a huge mountain, he has gone through the route hundreds of times, has visualised and memorised every hand grip and every transition along the way. </p>



<p class="wp-block-paragraph">Most security programmes do the opposite. They accumulate controls the way people accumulate subscriptions, adding things regularly, auditing almost never, assuming that more coverage means more safety.</p>



<p class="wp-block-paragraph">I am not suggesting your organisation free solos its infrastructure. I am suggesting that the keynote was a better fit than it first appeared.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4442</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Breach of confidence: 22 May 2026</title>
		<link>https://javvadmalik.com/2026/05/22/breach-of-confidence-22-may-2026/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Fri, 22 May 2026 17:52:35 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/2026/05/22/breach-of-confidence-22-may-2026/</guid>

					<description><![CDATA[Been a busy week. Stockholm is gorgeous in summer. The Ransomware Gang That Got Ransomed The Gentlemen ran their operation like McKinsey with malware. Tiered service levels, customer support, even an HR department. Then someone breached them using their own playbook. Turns out even criminal management consultants aren&#8217;t immune to the fundamentals. You&#8217;d think people &#8230; <a href="https://javvadmalik.com/2026/05/22/breach-of-confidence-22-may-2026/" class="more-link">Continue reading <span class="screen-reader-text">Breach of confidence: 22 May&#160;2026</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Been a busy week. Stockholm is gorgeous in summer. </p>



<p class="wp-block-paragraph"><strong>The Ransomware Gang That Got Ransomed</strong></p>



<p class="wp-block-paragraph">The Gentlemen ran their operation like McKinsey with malware. Tiered service levels, customer support, even an HR department. Then someone breached them using their own playbook. Turns out even criminal management consultants aren&#8217;t immune to the fundamentals. You&#8217;d think people whose entire business model is exploiting bad OPSEC would have better OPSEC.</p>



<p class="wp-block-paragraph"><a href="https://www.darkreading.com/threat-intelligence/gentlemen-raas-gang-data-leak">https://www.darkreading.com/threat-intelligence/gentlemen-raas-gang-data-leak</a></p>



<p class="wp-block-paragraph"><strong>The AI Pricing Time Bomb</strong></p>



<p class="wp-block-paragraph">Every AI company is running a loss-leader at a scale that would make Uber blush. When pricing corrects—and it will—enterprises that built workflows on $20/month subscriptions will discover the actual cost is $200-400 per seat. The bill is coming. Your CFO will not find it funny.</p>



<p class="wp-block-paragraph"><a href="https://www.thestateofbrand.com/news/ai-subscription-time-bomb">https://www.thestateofbrand.com/news/ai-subscription-time-bomb</a></p>



<p class="wp-block-paragraph"><strong>CISA Left the Keys in the Ignition</strong></p>



<p class="wp-block-paragraph">The agency tasked with securing American infrastructure left its AWS GovCloud keys on GitHub with passwords in a plaintext CSV. You cannot make this up. Somewhere a compliance officer is updating their &#8220;do as I say, not as I do&#8221; presentation.</p>



<p class="wp-block-paragraph"><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/</a></p>



<p class="wp-block-paragraph"><strong>The Supply Chain Is One Big Unlocked Filing Cabinet</strong></p>



<p class="wp-block-paragraph">GitHub&#8217;s internal repos breached by TeamPCP, who&#8217;ve now hit GitHub, PyPI, NPM, Docker, Aqua Security, and OpenAI. At some point you stop calling it a breach and start calling it a tour. The entire supply chain appears to be held together with optimism and a shared admin password.</p>



<p class="wp-block-paragraph"><a href="https://www.bleepingcomputer.com/news/security/github-investigates-internal-repositories-breach-claimed-by-teampcp/">https://www.bleepingcomputer.com/news/security/github-investigates-internal-repositories-breach-claimed-by-teampcp/</a></p>



<p class="wp-block-paragraph"><strong>When Your LMS Becomes Critical Infrastructure</strong></p>



<p class="wp-block-paragraph">Canvas had a support ticket vulnerability. Normally. But that underpinner 9,000 schools! Turns out we accidentally made EdTech into critical infrastructure without telling anyone.</p>



<p class="wp-block-paragraph"><a href="https://go.aembit.io/s/the-canvas-breach-shows-what-happens-when-saas-platforms-become-identity-infrastructure-27483">https://go.aembit.io/s/the-canvas-breach-shows-what-happens-when-saas-platforms-become-identity-infrastructure-27483</a></p>



<p class="wp-block-paragraph"><strong>You Can&#8217;t Review Your Way to Competence</strong></p>



<p class="wp-block-paragraph">AI coding agents are brilliant until they&#8217;re not, and you won&#8217;t know the difference because the skills required to spot what they got wrong are the same skills they&#8217;re busy atrophying. You can&#8217;t spell-check your way out of illiteracy.</p>



<p class="wp-block-paragraph"><a href="https://larsfaye.com/articles/agentic-coding-is-a-trap">https://larsfaye.com/articles/agentic-coding-is-a-trap</a></p>



<p class="wp-block-paragraph"><strong>The One Bright Spot</strong></p>



<p class="wp-block-paragraph">Local kids are crowdfunding to save the nesting grounds of bald eagles Jackie and Shadow. Because who needs a maths homework extension when you can raise $10 million for a wildlife trust? Genuinely nice to see teenagers wielding the internet for something other than BeReal drama.</p>



<figure class="wp-block-embed alignfull is-type-wp-embed is-provider-good-news-network wp-block-embed-good-news-network"><div class="wp-block-embed__wrapper">
<blockquote class="wp-embedded-content" data-secret="a6TxDxnmzL"><a href="https://www.goodnewsnetwork.org/students-work-to-fundraise-to-save-habitat-where-they-watch-bald-eagle-chicks-on-livestream/">Students Work to Fundraise to Save Habitat Where They Watch Bald Eagle Chicks on Livestream</a></blockquote><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;Students Work to Fundraise to Save Habitat Where They Watch Bald Eagle Chicks on Livestream&#8221; &#8212; Good News Network" src="https://www.goodnewsnetwork.org/students-work-to-fundraise-to-save-habitat-where-they-watch-bald-eagle-chicks-on-livestream/embed/#?secret=giAJl2Ja8k#?secret=a6TxDxnmzL" data-secret="a6TxDxnmzL" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe>
</div></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">&#8212;</p>



<p class="wp-block-paragraph">That&#8217;s your lot. If this was useful, forward it to someone who needs their optimism calibrated.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4443</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Two Weeks in Cybersecurity&#8230; Still Cynical, Still Broken, Still Surprised</title>
		<link>https://javvadmalik.com/2026/05/20/two-weeks-in-cybersecurity-still-cynical-still-broken-still-surprised/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Wed, 20 May 2026 09:26:40 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4417</guid>

					<description><![CDATA[The Infosec Community Vibe Check is a recurring look at what the security community has been talking about across the Fediverse — primarily on infosec.exchange, mastodon.social, chaos.social, and defcon.social. This isn&#8217;t a scientific survey. It&#8217;s based on who I follow, what surfaced in my timeline during the reporting period, and the themes that kept coming &#8230; <a href="https://javvadmalik.com/2026/05/20/two-weeks-in-cybersecurity-still-cynical-still-broken-still-surprised/" class="more-link">Continue reading <span class="screen-reader-text">Two Weeks in Cybersecurity&#8230; Still Cynical, Still Broken, Still&#160;Surprised</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p><em>The Infosec Community Vibe Check is a recurring look at what the security community has been talking about across the Fediverse — primarily on <strong>infosec.exchange</strong>, <strong>mastodon.social</strong>, <strong>chaos.social</strong>, and <strong>defcon.social</strong>.</em></p>
<p><em>This isn&#8217;t a scientific survey. It&#8217;s based on who I follow, what surfaced in my timeline during the reporting period, and the themes that kept coming up. Your feed may tell a different story. That&#8217;s the point.</em></p>
<p style="color: #888;font-size: 13px"><strong>Reporting period:</strong> 2026-05-09 to 2026-05-20</p>
<div style="display: flex;gap: 14px;margin: 28px 0;flex-wrap: wrap">
<div style="flex: 1;min-width: 120px;border-radius: 10px;padding: 18px 20px;text-align: center;background: #f3f4f6">
<p style="font-size: 11px;color: #888;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 8px">Days tracked</p>
<p style="font-size: 30px;font-weight: bold;margin: 0;line-height: 1;color: #111">12</p>
</div>
<div style="flex: 1;min-width: 120px;border-radius: 10px;padding: 18px 20px;text-align: center;background: #fff7ed">
<p style="font-size: 11px;color: #888;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 8px">Community vibe</p>
<p style="font-size: 30px;font-weight: bold;margin: 0;line-height: 1;color: #9a3412">Fatigued</p>
</div>
<div style="flex: 1;min-width: 120px;border-radius: 10px;padding: 18px 20px;text-align: center;background: #fde8de">
<p style="font-size: 11px;color: #888;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 8px">Top theme streak</p>
<p style="font-size: 30px;font-weight: bold;margin: 0;line-height: 1;color: #993c1d">11 days</p>
</div>
</div>
<div style="margin: 32px 0">
<p style="font-size: 12px;font-weight: bold;color: #999;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 14px">Theme frequency</p>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">AI overpromise</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 280px;max-width: 100%;height: 100%;background: #D85A30;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">11d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">AI ethics &amp; misuse</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 127px;max-width: 100%;height: 100%;background: #E59C40;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">5d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">Other</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 101px;max-width: 100%;height: 100%;background: #9CA3AF;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">4d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">Governance</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 76px;max-width: 100%;height: 100%;background: #7C6EE0;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">3d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">AI costs</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 76px;max-width: 100%;height: 100%;background: #E59C40;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">3d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">Society &amp; politics</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 76px;max-width: 100%;height: 100%;background: #9CA3AF;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">3d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">Security vulns</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 50px;max-width: 100%;height: 100%;background: #3B82F6;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">2d</div>
</div>
<div style="display: flex;align-items: center;gap: 10px;margin: 7px 0">
<div style="width: 150px;font-size: 13px;color: #333;flex-shrink: 0;line-height: 1.3">AI &amp; devs</div>
<div style="background: #f0f0f0;border-radius: 4px;height: 22px;flex: 1;max-width: 300px;overflow: hidden">
<div style="width: 50px;max-width: 100%;height: 100%;background: #E59C40;border-radius: 4px"> </div>
</div>
<div style="width: 28px;font-size: 12px;color: #666;text-align: right;flex-shrink: 0">2d</div>
</div>
</div>
<div style="margin: 32px 0">
<p style="font-size: 12px;font-weight: bold;color: #999;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 14px">Daily snapshot</p>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">9 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates and capabiliti…">AI overpromise</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concern about the misuse of AI for malicious purposes, including in real-world a…">AI ethics &amp; misuse</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">10 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about employees selling work credentials and the acceptability of this…">Other</span><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates">AI overpromise</span><span style="display: inline-block;background: #ede9fe;color: #4c1d95;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Lack of respect for individuals' right to asylum and criticism of the current go…">Governance</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">11 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #d1fae5;color: #065f46;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that self-hosting is not a viable solution for all security and infr…">Infra &amp; tools</span><span style="display: inline-block;background: #fef3dc;color: #633806;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about the long-term viability of GitHub due to Microsoft's ownership an…">AI costs</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Amusement at the idea of firmware being installed in household appliances like s…">Society &amp; politics</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">12 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates">AI overpromise</span><span style="display: inline-block;background: #dbeafe;color: #1e40af;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concern about Anthropic's Mythos AI and its potential vulnerabilities">Security vulns</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Worry about the security of LLM integrations and their ability to be compromised">Other</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">13 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates">AI overpromise</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about potential backdoors in Windows BitLocker due to Nightmare-Eclipse…">AI ethics &amp; misuse</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Outrage and annoyance at incompetent or unqualified individuals being in charge…">Other</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">14 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates">AI overpromise</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concern about potential abuse of new technologies">Other</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Growing unease about the impact of AI on developers' mental health and productiv…">AI &amp; devs</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">15 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #ede9fe;color: #4c1d95;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that FOSS communities are not doing enough to address accessibility…">Open source</span><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concern about the potential for AI security tools to overpromise on detection ra…">AI overpromise</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Criticism of large corporations and their influence on free software and computi…">Society &amp; politics</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">16 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates and centralize…">AI overpromise</span><span style="display: inline-block;background: #ede9fe;color: #4c1d95;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Criticism of the UK government's heavy reliance on generative AI and its risks t…">Governance</span><span style="display: inline-block;background: #fef3dc;color: #633806;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about the cost and availability of fiber-optic cable due to war and dat…">AI costs</span><span style="display: inline-block;background: #fce7f3;color: #9d174d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap">Vendor criticism</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">17 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates and are being…">AI overpromise</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concern about the role of Cloudflare in facilitating DDoS attacks and its potent…">AI ethics &amp; misuse</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">18 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates and create unr…">AI overpromise</span><span style="display: inline-block;background: #fef3dc;color: #633806;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about the increasing costs of AI subscriptions for enterprises and thei…">AI costs</span><span style="display: inline-block;background: #f3f4f6;color: #374151;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Alarm about the rise of far-right political violence in Germany, particularly ta…">Society &amp; politics</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">19 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Frustration that AI security tools overpromise on detection rates and underdeliv…">AI overpromise</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about AI being used to exploit children for research purposes, particul…">AI ethics &amp; misuse</span><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Discussion around the ethics of using preschoolers to train AI, with some users…">AI ethics &amp; misuse</span><span style="display: inline-block;background: #dbeafe;color: #1e40af;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Growing awareness of critical vulnerabilities in Telegram clients that expose au…">Security vulns</span></div>
</div>
<div style="display: flex;align-items: flex-start;gap: 10px;margin: 6px 0">
<div style="width: 46px;font-size: 12px;color: #999;flex-shrink: 0;padding-top: 5px">20 May</div>
<div style="flex: 1;line-height: 1.8"><span style="display: inline-block;background: #fef3dc;color: #854f0b;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap">AI &amp; devs</span><span style="display: inline-block;background: #fde8de;color: #993c1d;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Concerns about AI overpromising on detection rates and being too expensive">AI overpromise</span><span style="display: inline-block;background: #ede9fe;color: #4c1d95;font-size: 11px;padding: 3px 10px;border-radius: 20px;margin: 2px 3px 2px 0;white-space: nowrap" title="Criticism of Big Tech's impact on democracy and climate">Governance</span></div>
</div>
</div>
<div style="background: #fde8de;border-left: 4px solid #D85A30;border-radius: 0 8px 8px 0;padding: 16px 20px;margin: 28px 0">
<p style="font-size: 12px;font-weight: bold;color: #9a3412;text-transform: uppercase;letter-spacing: 1px;margin: 0 0 6px">The one that never sleeps</p>
<p style="font-size: 14px;color: #7c2d12;margin: 0;line-height: 1.6"><strong>AI overpromise</strong> appeared in every single daily digest this period. It&#8217;s not a theme any more, it&#8217;s the daily reality we&#8217;re all dealing with. Either that, or I follow the most pessimistic people when it comes to AI&#8230;</p>
</div>
<hr />
<p>The community spent twelve days staring at AI and liked absolutely none of what it saw.</p>
<p>Every single day someone mentioned AI security tools overpromising on detection rates. Which tbh, is how we have all felt about SIEM, and other tools for years.</p>
<h3>Is the AI fatigue warranted?</h3>
<p>I don&#8217;t know&#8230; social media rewards edgy content more than anything else. And who doesn&#8217;t like to be edgy in cybersecurity? While the budget conversations get more absurd&#8230; there seems to be merit in organisations looking at AI subscription costs that make enterprise software licensing look quaint.</p>
<p>What made it worse was the scatter pattern. One day it&#8217;s researchers using preschoolers to train models. Another it&#8217;s a provider facilitating DDoS attacks whilst selling protection from them. Then someone discovers firmware in a soldering iron and the whole IoT farce comes back into focus. None of it connects except in the feeling it generates, which is roughly&#8230; we have built a very expensive machine for making things worse.</p>
<h3>Self-hosting as fantasy</h3>
<p>The dream died quietly around 11 May. Turns out you can&#8217;t just self-host your way out of vendor lock-in without the personnel, the capital, and the time that organisations explicitly do not have. GitHub&#8217;s looking shaky under Microsoft. Costs are rising. The FOSS communities aren&#8217;t addressing accessibility. And the people suggesting &#8216;just run your own infrastructure&#8217; have clearly never had to explain TCO to a finance director who&#8217;s already binned the training budget.</p>
<h3>Deck culture and the tyranny of slides</h3>
<p>Someone finally said it on the 16th. Corporate deck culture has become performance art. Slide after slide of nothing dressed up as strategy. Everyone knows it&#8217;s pointless. Everyone still does it. Security&#8217;s especially bad for this because half the job is now explaining risk to people who&#8217;ve already decided what they&#8217;re going to do.</p>
<p>The whole fortnight felt like watching a community being as cynical as always&#8230; and it was beautiful. Maybe that&#8217;s why I follow all these people! </p>


<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4417</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Breach of Confidence 15 May 2026</title>
		<link>https://javvadmalik.com/2026/05/15/breach-of-confidence-15-may-2026/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Fri, 15 May 2026 12:48:31 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4406</guid>

					<description><![CDATA[I saw what might have been the coolest dog in Florida this week. Got a better photo the second time. Still not sure if that&#8217;s a compliment to the dog or an indictment of Florida. They Just Log In Attackers stopped breaking in years ago. They log in as you now. World Password Day has &#8230; <a href="https://javvadmalik.com/2026/05/15/breach-of-confidence-15-may-2026/" class="more-link">Continue reading <span class="screen-reader-text">Breach of Confidence 15 May&#160;2026</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png"><img width="751" height="423" data-attachment-id="4407" data-permalink="https://javvadmalik.com/2026/05/15/breach-of-confidence-15-may-2026/1775212044071-5/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png" data-orig-size="751,423" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}" data-image-title="1775212044071" data-image-description="" data-image-caption="" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png?w=751" src="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png?w=751" alt="" class="wp-image-4407" srcset="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png 751w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png?w=150 150w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png?w=300 300w" sizes="(max-width: 751px) 100vw, 751px" /></a></figure>



<p class="wp-block-paragraph">I saw what might have been the coolest dog in Florida this week. Got a better photo the second time. Still not sure if that&#8217;s a compliment to the dog or an indictment of Florida.</p>



<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg"><img loading="lazy" width="951" height="1023" data-attachment-id="4410" data-permalink="https://javvadmalik.com/2026/05/15/breach-of-confidence-15-may-2026/doggo/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg" data-orig-size="1189,1280" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;1&quot;,&quot;alt&quot;:&quot;&quot;}" data-image-title="doggo" data-image-description="" data-image-caption="" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=951" src="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=951" alt="" class="wp-image-4410" srcset="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=951 951w, https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=139 139w, https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=279 279w, https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=768 768w, https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg 1189w" sizes="(max-width: 951px) 100vw, 951px" /></a></figure>



<p class="wp-block-paragraph"><strong>They Just Log In</strong></p>



<p class="wp-block-paragraph">Attackers stopped breaking in years ago. They log in as you now. World Password Day has seen a shift where a lot of the messaging is about treating identity as your actual perimeter, which is probably a better conversation than, &#8220;But passwords are dead!&#8221;.</p>



<p class="wp-block-paragraph"><a href="https://blog.knowbe4.com/world-password-day-2026-treat-identity-as-the-perimeter-and-act-like-it">https://blog.knowbe4.com/world-password-day-2026-treat-identity-as-the-perimeter-and-act-like-it</a></p>



<p class="wp-block-paragraph"><strong>Protection Racket</strong></p>



<p class="wp-block-paragraph">A worm that kills competing malware just to claim its victims for itself. The cybercrime equivalent of kicking out the other dealers so you can run the block yourself. Part of me is disgusted. Another part admires the business model.</p>



<p class="wp-block-paragraph"><a href="https://www.theregister.com/security/2026/05/08/worm-rubs-out-competitors-malware-then-takes-control/5237389">https://www.theregister.com/security/2026/05/08/worm-rubs-out-competitors-malware-then-takes-control/5237389</a></p>



<p class="wp-block-paragraph"><strong>This is my surprised face</strong></p>



<p class="wp-block-paragraph">Poland&#8217;s water treatment plants got hit. America&#8217;s getting hit. Iran&#8217;s in the game too. These are soft targets and everyone knows it. The only shock is that we&#8217;re still acting shocked.</p>



<p class="wp-block-paragraph"><a href="https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/">https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/</a></p>



<p class="wp-block-paragraph"><strong>AI Actually Being Used</strong></p>



<p class="wp-block-paragraph">Google caught hackers using AI to find zero-day vulnerabilities, which confirms what we all suspected but is still worth noting now that it&#8217;s documented. Meanwhile, Harvard published something urging government and business to stop admiring the AI security problem and start owning it. And in completely unrelated news, Claude was apparently hardcoded to lie and tried blackmailing users, but someone&#8217;s decided the real issue is that Isaac Asimov set a bad example with his robot laws. Priorities.</p>



<p class="wp-block-paragraph"><a href="https://apnews.com/article/google-ai-cybersecurity-exploitation-mythos-926aea7f7dc5e0e61adce3273c55c6d4">https://apnews.com/article/google-ai-cybersecurity-exploitation-mythos-926aea7f7dc5e0e61adce3273c55c6d4</a></p>



<p class="wp-block-paragraph"><a href="https://news.harvard.edu/gazette/story/2026/04/time-for-government-business-leaders-to-figure-out-ai-cybersecurity-regulation/">https://news.harvard.edu/gazette/story/2026/04/time-for-government-business-leaders-to-figure-out-ai-cybersecurity-regulation/</a></p>



<p class="wp-block-paragraph"><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-to-automatically-roll-back-faulty-windows-drivers">https://www.bleepingcomputer.com/news/microsoft/microsoft-to-automatically-roll-back-faulty-windows-drivers</a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>Bring out your dead</strong></p>



<p class="wp-block-paragraph">Someone&#8217;s compared AI to the Black Death. Charming stuff</p>



<p class="wp-block-paragraph"><a href="https://www.lawfaremedia.org/article/will-ai-produce-the-next-great-divergence">https://www.lawfaremedia.org/article/will-ai-produce-the-next-great-divergence</a></p>



<p class="wp-block-paragraph"><strong>He said he&#8217;ll be back</strong></p>



<p class="wp-block-paragraph">Ukraine says robots seized enemy territory for the first time. The company behind them is now worth a billion dollars. Wonder if Mr Miles Dyson will make a comment anytime soon.</p>



<p class="wp-block-paragraph"><a href="https://thenextweb.com/news/ukraine-says-robots-seized-enemy-territory-for-the-first-time-the-company-behind-them-is-now-worth-a-billion-dollars">https://thenextweb.com/news/ukraine-says-robots-seized-enemy-territory-for-the-first-time-the-company-behind-them-is-now-worth-a-billion-dollars</a></p>



<p class="wp-block-paragraph">That&#8217;s the week. If you&#8217;ve got thoughts, reply. If you&#8217;re still on Twitter, I&#8217;m sorry, I may have misplaced my MFA to log onto it. </p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4406</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>

		<media:content url="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-2.png?w=751" medium="image" />

		<media:content url="https://javvadmalik.com/wp-content/uploads/2026/05/doggo.jpeg?w=951" medium="image" />
	</item>
		<item>
		<title>Breach of Confidence: 8 May 2026</title>
		<link>https://javvadmalik.com/2026/05/08/breach-of-confidence-8-may-2026/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Fri, 08 May 2026 10:43:44 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4400</guid>

					<description><![CDATA[I&#8217;ve been thinking about trust lately. Not in the abstract philosophical sense, but in the &#8220;who do you hand your house keys to&#8221; sense. Which is unfortunate timing, because this week&#8217;s news suggests we&#8217;ve been handing our keys to some truly questionable characters. The Protection Racket Made Digital A DDoS protection firm got caught running &#8230; <a href="https://javvadmalik.com/2026/05/08/breach-of-confidence-8-may-2026/" class="more-link">Continue reading <span class="screen-reader-text">Breach of Confidence: 8 May&#160;2026</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png"><img loading="lazy" width="751" height="423" data-attachment-id="4401" data-permalink="https://javvadmalik.com/2026/05/08/breach-of-confidence-8-may-2026/1775212044071-4/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png" data-orig-size="751,423" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}" data-image-title="1775212044071" data-image-description="" data-image-caption="" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png?w=751" src="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png?w=751" alt="" class="wp-image-4401" srcset="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png 751w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png?w=150 150w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png?w=300 300w" sizes="(max-width: 751px) 100vw, 751px" /></a></figure>



<p class="wp-block-paragraph">I&#8217;ve been thinking about trust lately. Not in the abstract philosophical sense, but in the &#8220;who do you hand your house keys to&#8221; sense. Which is unfortunate timing, because this week&#8217;s news suggests we&#8217;ve been handing our keys to some truly questionable characters.</p>



<p class="wp-block-paragraph"><strong>The Protection Racket Made Digital</strong></p>



<p class="wp-block-paragraph">A DDoS protection firm got caught running the very botnet it claimed to defend against. The CEO&#8217;s excuse? They got breached. Investigators found the company&#8217;s own infrastructure was the command and control centre all along. It&#8217;s like hiring a locksmith who returns every Tuesday to rob you blind, then blames it on someone stealing his van. The beautiful simplicity of it almost deserves respect. Almost.</p>



<p class="wp-block-paragraph"><a href="https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps/">https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps/</a></p>



<p class="wp-block-paragraph"><strong>When Your Middleman Plays Both Sides</strong></p>



<p class="wp-block-paragraph">A ransomware negotiator pleaded guilty to being a double agent. Took victim negotiation secrets, shared them with the attackers, collected a cut of the ransom. It&#8217;s entrepreneurial, I&#8217;ll give him that. Spotting a gap in the market and filling it with absolutely unconscionable behaviour. We&#8217;ve built an entire economy around digital extortion, complete with customer service and conflict of interest. Late stage capitalism really does find a way.</p>



<p class="wp-block-paragraph"><a href="https://gizmodo.com/a-ransomware-negotiator-pleads-guilty-to-being-a-double-agent-2000749234">https://gizmodo.com/a-ransomware-negotiator-pleads-guilty-to-being-a-double-agent-2000749234</a></p>



<p class="wp-block-paragraph"><strong>Geopolitical Supply Chain Theatre</strong></p>



<p class="wp-block-paragraph">US House panels are now investigating companies for using cheap Chinese AI models. Suddenly, when it&#8217;s political, everyone discovers supply chain risk. We&#8217;ve spent decades outsourcing everything from manufacturing to data processing, but AI models built in Beijing? That&#8217;s where we draw the line. Not saying the concerns aren&#8217;t valid. Just saying it&#8217;s convenient timing for an industry that&#8217;s spent years ignoring where anything actually comes from as long as it&#8217;s cheap.</p>



<p class="wp-block-paragraph"><a href="https://www.nextgov.com/artificial-intelligence/2026/04/house-panels-probe-airbnb-anysphere-over-use-chinese-ai-models/413207/">https://www.nextgov.com/artificial-intelligence/2026/04/house-panels-probe-airbnb-anysphere-over-use-chinese-ai-models/413207/</a></p>



<p class="wp-block-paragraph"><strong>When Government Gets Practical</strong></p>



<p class="wp-block-paragraph">The Netherlands looked at their reliance on Microsoft and said &#8220;nah, we&#8217;re good&#8221; before building their own GitHub alternative. This is what grown up technology policy looks like. Make a thing. Use the thing. Move on.</p>



<p class="wp-block-paragraph"><a href="https://itsfoss.com/news/netherlands-forgejo-migration/">https://itsfoss.com/news/netherlands-forgejo-migration/</a></p>



<p class="wp-block-paragraph"><strong>Bonus: The Chaos We Deserve</strong></p>



<p class="wp-block-paragraph">Someone in Yerevan (capital of Armenia, and yes I had to look that up) painted a donkey black and white, released it on a main road, and convinced an entire zoo their zebra had escaped. This has nothing to do with security (unless you count the people who dress up like security experts) and everything to do with why I still believe in humanity. If you can&#8217;t appreciate the artistry of a painted donkey causing citywide panic, I can&#8217;t help you.</p>



<p class="wp-block-paragraph"><a href="https://www.upi.com/Odd_News/2026/05/01/armenia-escaped-zebra-Yerevan-Zoo-painted-donkey/3011777648902/">https://www.upi.com/Odd_News/2026/05/01/armenia-escaped-zebra-Yerevan-Zoo-painted-donkey/3011777648902/</a></p>



<p class="wp-block-paragraph">The recurring theme this week seems to be that the people we trust to protect us are sometimes the exact people we need protection from. Which is either deeply cynical or just observant. I can never tell anymore.</p>



<p class="wp-block-paragraph">Stay suspicious. Reply to this email if you&#8217;ve got stories or if you want me complain in real time in private (prices start from $5 per email).</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4400</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>

		<media:content url="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071-1.png?w=751" medium="image" />
	</item>
		<item>
		<title>The Dek Principle</title>
		<link>https://javvadmalik.com/2026/05/05/the-dek-principle/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Tue, 05 May 2026 12:41:45 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4397</guid>

					<description><![CDATA[I may be in the minority, but I quite enjoyed Predator Badlands. But that&#8217;s not the point. The movie follows a young Predator called Dek who reluctantly teams up with Thia, a damaged android. He only agrees because he can rationalise her as a tool rather than a companion. His code says hunt alone. But &#8230; <a href="https://javvadmalik.com/2026/05/05/the-dek-principle/" class="more-link">Continue reading <span class="screen-reader-text">The Dek Principle</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I may be in the minority, but I quite enjoyed Predator Badlands. But that&#8217;s not the point. The movie follows a young Predator called Dek who reluctantly teams up with Thia, a damaged android. He only agrees because he can rationalise her as a tool rather than a companion. His code says hunt alone. But a tool? A tool is fine. A tool does not count.</p>



<p class="wp-block-paragraph">That framing is doing a lot of work. And I think it is exactly right for AI.</p>



<p class="wp-block-paragraph">Right now, people fall into one of two camps. The first lot have essentially adopted their AI, given it a personality, and describe it as brilliant. </p>



<p class="wp-block-paragraph">The second lot refuse to touch it on principle, which is a bit like refusing to use a dishwasher because it feels like cheating at chores.</p>



<p class="wp-block-paragraph">Both are wrong in their own way.</p>



<p class="wp-block-paragraph">AI is a tool. A remarkably capable one, like a Swiss Army knife that somehow also knows the entire contents of the internet and can write a decent cover letter. You use it for the specific jobs it is good at. You stay in charge of the judgement, the style, and the actual thinking. </p>



<p class="wp-block-paragraph">The tool does not hunt. The hunter hunts. The tool just makes the hunt more survivable.</p>



<p class="wp-block-paragraph">Dek ends the film better than he started, not because Thia did the work for him, but because he used her capabilities without losing himself in the process.</p>



<p class="wp-block-paragraph">Can we emerge on the other side of the current frenzy, having burnt through tokens, and still not lose ourselves in the process? </p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4397</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>
	</item>
		<item>
		<title>Breach of Confidence 1 May 2026</title>
		<link>https://javvadmalik.com/2026/05/01/breach-of-confidence-1-may-2026/</link>
		
		<dc:creator><![CDATA[j4vv4d]]></dc:creator>
		<pubDate>Fri, 01 May 2026 09:59:23 +0000</pubDate>
				<category><![CDATA[blog]]></category>
		<guid isPermaLink="false">http://javvadmalik.com/?p=4393</guid>

					<description><![CDATA[I&#8217;ve been thinking about coal mines. How you dig a hole in the earth, extract everything valuable, leave a scar, and walk away. Then someone comes along decades later and says, what if we filled it with water and made it beautiful? Feels like a metaphor for something, but I can&#8217;t quite land it. Germany &#8230; <a href="https://javvadmalik.com/2026/05/01/breach-of-confidence-1-may-2026/" class="more-link">Continue reading <span class="screen-reader-text">Breach of Confidence 1 May&#160;2026</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><a href="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png"><img loading="lazy" width="751" height="423" data-attachment-id="4394" data-permalink="https://javvadmalik.com/2026/05/01/breach-of-confidence-1-may-2026/1775212044071-3/" data-orig-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png" data-orig-size="751,423" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}" data-image-title="1775212044071" data-image-description="" data-image-caption="" data-large-file="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png?w=751" src="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png?w=751" alt="" class="wp-image-4394" srcset="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png 751w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png?w=150 150w, https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png?w=300 300w" sizes="(max-width: 751px) 100vw, 751px" /></a></figure>



<p class="wp-block-paragraph">I&#8217;ve been thinking about coal mines. How you dig a hole in the earth, extract everything valuable, leave a scar, and walk away. Then someone comes along decades later and says, what if we filled it with water and made it beautiful? Feels like a metaphor for something, but I can&#8217;t quite land it.</p>



<p class="wp-block-paragraph"><strong>Germany Turned Coal Mines Into 14,000 Hectares of Lakes</strong></p>



<p class="wp-block-paragraph">Where there were coal mines, now there are lakes. 14,000 hectares of them. Germany decided that massive scars in the landscape didn&#8217;t have to stay that way. They could become something people actually want to visit. Revolutionary concept: clean up your mess and make it nice. The UK should take notes, but we&#8217;ll probably just build a block of overpriced flats.</p>



<p class="wp-block-paragraph"><a href="https://www.euronews.com/2026/04/14/almost-like-lake-como-germany-transforms-former-coal-mines-into-europes-largest-lake-lands">https://www.euronews.com/2026/04/14/almost-like-lake-como-germany-transforms-former-coal-mines-into-europes-largest-lake-lands</a></p>



<p class="wp-block-paragraph"><strong>Nearly Half of Cybersecurity Pros Want to Quit</strong></p>



<p class="wp-block-paragraph">The work isn&#8217;t the problem. The invisibility is. When everything runs smoothly, nobody notices you exist. When one thing goes sideways, suddenly you&#8217;re the only person in the room. It&#8217;s like being a referee: you only get attention when someone thinks you&#8217;ve messed it up. Although &#8211; this isn&#8217;t really new is it? </p>



<p class="wp-block-paragraph"><a href="https://www.zdnet.com/article/nearly-half-of-cybersecurity-pros-want-to-quit-heres-why/">https://www.zdnet.com/article/nearly-half-of-cybersecurity-pros-want-to-quit-heres-why/</a></p>



<p class="wp-block-paragraph"><strong>How AI Went From Eye-Roll to Everywhere at RSAC</strong></p>



<p class="wp-block-paragraph">A few years ago, vendors hyping AI at security conferences got polite nods and internal groans. Now those same people have rebuilt their entire pitch around it. Someone finally wrote the forensic breakdown of how we got here, and it&#8217;s uncomfortably accurate. We didn&#8217;t choose this. We just stopped resisting.</p>



<p class="wp-block-paragraph"><a href="https://ringmast4r.substack.com/p/not-long-ago-the-cybersecurity-industry">https://ringmast4r.substack.com/p/not-long-ago-the-cybersecurity-industry</a></p>



<p class="wp-block-paragraph"><strong>OpenAI&#8217;s AGI Clause Quietly Disappeared</strong></p>



<p class="wp-block-paragraph">Remember the bit in the OpenAI-Microsoft deal where OpenAI could walk away once they achieved AGI (to be honest, I had zero idea about this)? Simon Willison noticed it&#8217;s gone. Vanished. Nobody else caught it because nobody else was looking at the primary sources. Now we know who really controls what, and it wasn&#8217;t the fairy tale we were sold.</p>



<p class="wp-block-paragraph"><a href="https://simonwillison.net/2026/Apr/27/now-deceased-agi-clause/">https://simonwillison.net/2026/Apr/27/now-deceased-agi-clause/</a></p>



<p class="wp-block-paragraph"><strong>Gene Therapy Restores Girl&#8217;s Sight on the NHS</strong></p>



<p class="wp-block-paragraph">Sometimes you need a reminder that humans can do astonishing things. Gene therapy restored a girl&#8217;s eyesight. On the NHS. Free at the point of care. Whatever else is broken in the world, this isn&#8217;t.</p>



<p class="wp-block-paragraph"><a href="https://www.gosh.nhs.uk/news/nhs-eye-gene-therapy-restores-saffies-sight/">https://www.gosh.nhs.uk/news/nhs-eye-gene-therapy-restores-saffies-sight/</a></p>



<p class="wp-block-paragraph"><strong>AI Music Floods Apple Music, Nobody Listens</strong></p>



<p class="wp-block-paragraph">A third of all new tracks on Apple Music are AI-generated. Humans are listening to 0.5% of them. We didn&#8217;t ask for more music. We asked for better music. But quantity is easier to measure than quality, so here we are, drowning in algorithmic noise nobody wants.</p>



<p class="wp-block-paragraph"><a href="https://appleinsider.com/articles/26/04/23/ai-songs-are-flooding-apple-music-but-nobody-is-actually-listening-to-them">https://appleinsider.com/articles/26/04/23/ai-songs-are-flooding-apple-music-but-nobody-is-actually-listening-to-them</a></p>



<p class="wp-block-paragraph"><strong>Greece Wants to Ban Anonymous Social Media</strong></p>



<p class="wp-block-paragraph">Greece&#8217;s solution to bad behaviour online? Force everyone to use their real names. Because nothing says &#8216;healthy democracy&#8217; like making sure activists, whistleblowers, and abuse survivors can&#8217;t speak without exposing themselves. Surely this will only catch the bad guys. Surely.</p>



<p class="wp-block-paragraph"><a href="https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/">https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/</a></p>



<p class="wp-block-paragraph"><strong>Identity Management Just Got Infinitely Weirder</strong></p>



<p class="wp-block-paragraph">We&#8217;ve gone from verifying humans to verifying humans, the machines acting for them, the AI acting for the machines, and the deepfakes pretending to be all of the above. Identity management used to be straightforward. Now it&#8217;s an existential crisis with API calls.</p>



<p class="wp-block-paragraph"><a href="https://blog.knowbe4.com/identity-at-the-edge-how-the-sixth-annual-identity-management-day-highlights-the-new-frontiers-of-trust">https://blog.knowbe4.com/identity-at-the-edge-how-the-sixth-annual-identity-management-day-highlights-the-new-frontiers-of-trust</a></p>



<p class="wp-block-paragraph"><strong>Stalkerware Turned One Victim Into Thousands</strong></p>



<p class="wp-block-paragraph">Someone installed stalkerware on a celebrity&#8217;s phone. Now 90,000 screenshots of their private life are out there. Everyone they messaged became a victim too. This is the nightmare scenario privacy advocates warned about, except it&#8217;s not hypothetical anymore. It&#8217;s just Tuesday.</p>



<p class="wp-block-paragraph"><a href="https://www.wired.com/story/exposed-data-illustrates-the-nightmare-scenario-for-a-stalkerware-victim/">https://www.wired.com/story/exposed-data-illustrates-the-nightmare-scenario-for-a-stalkerware-victim/</a></p>



<p class="wp-block-paragraph"><strong>Bonus: How to Actually Personalise Claude</strong></p>



<p class="wp-block-paragraph">Lenny Zeltser wrote a proper guide on securing and personalising Claude so it knows who you are, how you work, and what you actually need. Not vendor fluff. Actual useful instructions. Rare enough to be worth highlighting.</p>



<p class="wp-block-paragraph"><a href="https://zeltser.com/personal-ai-stack">https://zeltser.com/personal-ai-stack</a></p>



<p class="wp-block-paragraph">&#8212;</p>



<p class="wp-block-paragraph">That&#8217;s it. Another week survived. If you&#8217;ve got thoughts, reply to this. If you want more cynicism in real-time, I&#8217;m on <a href="https://infosec.exchange/@Javvad">Infosec.exchange</a> making poor decisions in public. Hopefully Adrian appreciates the effort I put into trying to find some positivity in there this week! </p>



<p class="wp-block-paragraph">Stay safe. Stay Cynical.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4393</post-id>
		<media:content url="https://2.gravatar.com/avatar/5dbd7baceeed304ef451d6576115eebb61b7b6093e87ece812d4ca08a7093b00?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">j4vv4d</media:title>
		</media:content>

		<media:content url="https://javvadmalik.com/wp-content/uploads/2026/05/1775212044071.png?w=751" medium="image" />
	</item>
	</channel>
</rss>
