blog 2 Minutes

I’ve been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don’t have vendors.
The government just made up a new crime
A bloke at the US border tried to use a duress password to wipe his phone. Now he’s being prosecuted for destroying his own device. Nobody passed a law saying this was illegal. They’re just calling it obstruction and hoping it sticks. Case law written by customs officers with an agenda. Grand.
The phishing campaign that deserved applause
Belarusian activists in exile are getting spear-phished with the kind of precision you’d normally see in state-sponsored ops. One activist in Lithuania caught it: the site cloaked itself to dodge security scanners, the message used Latin characters disguised as Cyrillic, and follow-ups echoed the victim’s own device details back at them. I’m part disgusted, but also slightly admiring the professionalism. Whoever’s running this one deserves a drink. So does the person who spotted it.
Malware with an MBA
Dolphin X malware now allegedly uses AI to automatically rank and prioritise high-value victims. We’ve moved from attackers manually choosing targets to letting an algorithm do the triage. Efficiency gains in crime. What a time to be alive.
Microsoft discovers how large enterprises actually work
Microsoft has ordered admins to patch systems within three days. Enterprises with change control boards, testing protocols, and the memory of what happened last time they rushed a deployment just laughed so hard they needed a restart. The directive assumes IT departments operate like a laptop in a coffee shop, not like a refinery that can’t afford five minutes of unplanned downtime.
The one who got away
Phineas Fisher hacked spyware companies, funded resistance movements, published the playbooks, and vanished. A decade later, still free. No arrests, no unmasking, no dramatic takedown. Just gone.
https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/
We found new spyware that wasn’t new
Researchers discovered spyware nobody had seen before. Then they realised they’d actually seen it years ago. They just didn’t know what they were looking at. Pattern recognition only works if you know what the pattern means.
https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3
Anthropic learns nothing from the privacy playbook
Shared Claude conversations ended up publicly indexed on Google. Anthropic’s response amounted to ‘you shouldn’t have shared them then.’ Technically correct. Utterly tone-deaf. A masterclass in not reading the room.
Passkeys meet the same old attacks in new clothes
We spent years celebrating passkeys as the thing that finally kills phishing and credential stuffing. Turns out the attacks just changed uniforms. Implementation flaws mean old techniques still work. We’ve swapped the lock but kept the same dodgy door frame.
The worst aquarium ever
A whaling museum got called ‘the worst aquarium ever’ in a review. Instead of ignoring it, they put it on a t-shirt. Sold 738 in 30 hours. The lesson isn’t about spinning bad press into good marketing. It’s about having the spine to own what you actually are, not what people expected. Security teams could learn from this.
https://www.wbur.org/news/2026/07/27/new-bedford-whaling-museum-worst-aquarium-ever-merch
—
That’s your week. If you’ve got a story I missed or just want to tell me I’m wrong about something, hit reply. I read them all, even the ones telling me I’m a muppet.
Stay cynical.