There is no such thing as a technical decision that isn’t also a risk decision.
Every firewall rule is a statement about what an organisation is willing to lose. Every service account holding more permission than it needs is a risk somebody accepted, usually without knowing they were accepting it. The industry keeps these two conversations in separate rooms — engineers in one, governance in the other — and attackers make their living in the gap between them.
This site refuses the separation.
What this is
A knowledge base about AI-driven and AI-automated attacks, written for the people who have to do something about it. That means two readers who are usually served separately and shouldn’t be: the one configuring the system, and the one accountable for the risk.
AI-enabled attack is, I think, the most consequential shift in the threat landscape right now — not because the tooling is magic, but because it collapses the cost of things that used to require patience and skill. Credential stuffing at a scale that once needed a team. Reconnaissance that once took weeks. Agents handed organisation-wide read access to do one narrow job, because scoping them properly was harder than not bothering.
None of that is a technical problem or a governance problem. It is both, and treating it as either one alone is how organisations get hurt.
What I commit to
The point of this site is that you can act on what’s here. That requires a standard.
Primary sources, linked. Vendor advisories, the CVE record, CISA KEV, the researcher’s own writeup. If a claim on this site can’t be traced to something you can check yourself, it doesn’t belong here.
Applicability before severity. CVSS 10.0 means nothing if the product isn’t in your estate. Affected versions, affected models, what is explicitly not affected, whether exploitation requires authentication. Your first question is whether this is your problem at all. That gets answered first.
Uncertainty stated, not smoothed. Where sources disagree, I will say so and show both. Figures get ranges and attribution rather than a confident round number. “Confirmed by the vendor” and “reported by one researcher” are different claims and will be labelled as such.
Slow where slow is more accurate. This site will not be first. Same-week analysis of a live incident is usually wrong in precisely the details that matter, and the details that matter are the entire point.
Corrections in public. Appended, dated, with the original text left visible. If something here was wrong, the record of it having been wrong stays up.
What this isn’t
Not a news feed — there are better ones, properly staffed and faster than I will ever be. Not vendor commentary. Not a personal brand: my name is on this because somebody should be accountable for it, not because the subject is me.
The only measure that matters is whether a practitioner who checked something here and acted on it was right to.
— Nathan Cocker

Leave a Reply