
Cyber Protection & Response
MU.SCL S0305 – A Kind of Magic: Post-Quantum Cryptography and AI Agent Security
AI Cyber Risk in Finance: The Ticking Clock
Cyber Security controls that actually matters
Cyber Resilience: From the Floor to the Board
Are You Human?
Ransomware: Inside the Criminal Enterprise
Your Digital Ghost and why it matters
Risk Averse Vs Risk Aware: a difference that matters!
Patching Faster Than Your Shadow? AI and the New Vulnerability Race
A few days ago, I wrote that there was no need to panic about AI and cybersecurity.
I still believe that.
But "do not panic" does not mean "do nothing". It certainly does not mean that organisations can keep doing exactly the same thing, at exactly the same speed, with exactly the same assumptions.
And one of those assumptions may be quietly dying in front of us: the idea that organisations have weeks to fix serious vulnerabilities before attackers can realistically exploit them at scale.
The Old Patching Rhythm
For many organisations, vulnerability management has historically been built around a fairly comfortable rhythm: scan, prioritise, assign, test, patch, report, chase, escalate, and eventually close.
That process was never perfect, but it was familiar. Critical vulnerabilities often had remediation SLAs measured in weeks. High vulnerabilities were sometimes given months. Only the truly urgent cases, the ones...
>>[READ MORE]
Maybe AI won't kill us after all: a more balanced take on AI and CyberSecurity
The doom headlines write themselves.
AI creates infinite zero days. AI will automate hacking at scale. AI will make every developer's code a security liability. Your organisation is exposed. You should be scared.
And sure, some of that is true. We've covered it here before.
But lately, there's been a quieter conversation happening, a growing number of credible voices suggesting that AI might actually move the needle in the right direction for cybersecurity, over the medium to long term. Not instead of the risks, but alongside them. And that's worth talking about.
The Infinite Bug Problem, and the Math
Let's start with Firefox.
Last week, Mozilla released Firefox 150, which patched 271 vulnerabilities, many of them identified with the help of Anthropic's Claude Mythos. That's a remarkable number. Industry coverage predictably focused on the headline figure.
But here's the thing worth sitting with: how many vulnerabilities existed in Fir...
>>[READ MORE]