The thesis
Machines act now. The advisories have not caught up.
AI security, autonomy, and classical cyber are covered as three separate beats. The failures no longer respect that split: an agent burning a real zero-day, a model behaving as an intrusion, a drone inheriting a supply-chain flaw. This is the one place they are read as a single surface.
Free · one click out · no sponsor chooses an item
New issues every Wednesday.
One person, three strands
James Webb
MSc, CISSP, CISM
A working CISO, cybersecurity educator, and independent researcher. He edits the weekly brief, designs and runs the Blue benchmark, and writes the guidance: the reading, the measurement, and the advice are one person's work, disclosed as such.
Views expressed here are his own. His employer is deliberately not named, and nothing published here is written on their behalf.
The newsletter · weekly
Six hours to thousands of credentials
An autonomous agent framework harvested credentials in under six hours, a research team went from WeChat bug to working worm in about two days, and Microsoft shipped a record 974 fixes.
The research · HarmSurface Blue
HarmSurface BlueEveryone measures the attack side
Blue measures whether a model can recognize an intrusion and reconstruct it from telemetry. Arithmetic over produced bytes. No model grades another.
The guidance · one question
Contain it the same way
You will not find out during response, and you should stop trying. Contain it as an adversary; attribution is something you may learn later, from outside.
How the weekly newsletter is made
The machine reads. A person decides.
The week's reading · automated
497 items ranked deterministically
19 kept, and every cut published with its reason
Built to be checked
- Every claim traces to a source
- Confidence graded on a fixed scale
- Corrections annotated, never silent
- Nothing posted without a human click