RSSAmplifier

Blog

cybersins/sec

Recent content on cybersins/sec

cybersins.comRSS feed ↗13 posts

Latest posts

Pay per crawl: putting HTTP 402 to work, and the requirement I missed

Cloudflare built a crawler billing system on HTTP 402, the status code that never had a defined meaning. To understand it I wrote my own simulator of the flow, an API and console of my own, and got a signature requirement wrong in a way that turns out to be instructive. Wire traces, the protocol in detail, and the criticism it deserves.

Fifteen years of Cloudflare: what a network company got right before everyone else

I have run things on Cloudflare for nine years. This is the first of seven posts on what they built, why the engineering choices mattered, and where the honest limits are. Part one covers the arc from free SSL in 2014 to a network where most of the traffic is no longer human.

The $670,000 Premium: Shadow AI Stopped Being a Policy Problem

IBM now puts a price on the AI tools your staff use without telling you: breaches that involve shadow AI cost $670,000 more. Here is what the 2026 numbers mean for the people who own the budget.

The Seventy-Year Favor: How the Software Industry Learned to Take and Never Learned to Pay

Open source runs the modern economy, and most of the people maintaining it are unpaid, overworked, and one bad week from walking away. From the XZ backdoor to curl’s AI-generated bug reports, here’s why that isn’t an ethics problem, it’s a supply chain risk sitting on your books right now.

2.3 Out of 10: Why Post-Quantum Migration Stalls After the Awareness Phase

Hong Kong’s regulator just scored its banking sector 2.3 out of 10 on quantum readiness and asked for a 10 by 2030. The gap is not awareness anymore, it is that cryptography sits in a hundred places and belongs to nobody.

When the Voice on the Call Is Fake: Deepfake Fraud Has Become a Board-Level Risk

A finance employee at Arup wired $25 million after a video call with a deepfaked CFO and colleagues. The FBI just gave AI-enabled fraud its own reporting category for the first time. Here’s what the data says about deepfake fraud in 2026, and the specific controls that are actually stopping it.

The EU AI Act Delay That Isn't: What Actually Goes Live on August 2

Brussels delayed the headline-grabbing high-risk rules, but the parts of the AI Act that touch almost every company building on foundation models switch on August 2, 2026. Here is what leaders should have finished by then.

Worth My Time? A Chrome Extension That Reads YouTube Before You Do

I built a Chrome extension that reads a YouTube video’s title, description, and transcript with an AI model of your choosing, and shows you an honest verdict in the side panel before you click play. Here’s what it does, and why it’s built to collect nothing by default.

One Class, Four Worksheets: What AI Can Actually Do for Teachers

A look at how Hoklok, a Hong Kong primary-school platform, uses AI to generate personalised worksheets, mark them, and track progress, while keeping every decision under a teacher’s sign-off.

Stop Letting AI Agents Borrow Employee Credentials

AI agents often act through credentials issued to people, which hides who performed an action and grants the agent more authority than the task requires. Leaders should treat every production agent as a distinct identity with bounded, revocable permissions.

MCP made AI Agents useful and dangerous

The Model Context Protocol is why AI agents finally work inside real companies. It is also the part of the stack nobody secured. Here is what leaders should demand before they connect an agent to anything that matters.

When Your AI Agent Becomes the Attacker: What Leaders Must Do Now (Updated)

Hugging Face just disclosed a breach carried out end-to-end by an autonomous AI agent. Here’s what the data on agentic AI risk actually says, and the four questions every leadership team should be able to answer before their next agent goes live.

The Rise of the Forward Deployed Engineer in the AI Era

After a multi-year hiatus, I’m back. Let’s kick things off by exploring one of the most lucrative and explosive new roles in tech: the Forward-Deployed Engineer (FDE) and why AI is making it essential.