RSSAmplifier

Blog

Simon Roses Femerling – Blog

CyberSpace Insecurity 3.X

simonroses.comRSS feed ↗13 posts

Latest posts

When a Missing Patch Becomes a Defective Product: The New EU Product Liability Directive

**Read Time:** 13 minutes ## TL;DR On **December 9, 2026** — a few months from now — the new EU Product Liability Directive ((EU) 2024/2853, “PLD”) starts applying to products placed on the EU market. For the first time, **software … Continue reading →

The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live

**Read Time:** 13 minutes ## TL;DR On **August 2, 2026**, the part of the EU AI Act everyone was quietly ignoring became enforceable: the AI Office can now fine providers of general-purpose AI models **up to 3% of global annual … Continue reading →

The Future of Vibe Coding Security (Part 10)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…

Do Open Weight Models Dream of Tokens?

**Read Time:** 14 minutes ## TL;DR Philip K. Dick asked whether an android could be told from a human. In 2026 the enterprise version of that question is whether you can still tell an open-weight model from a frontier commercial … Continue reading →

When the Model Is the Attacker: The Hugging Face / OpenAI Model-Evaluation Incident

**Read Time:** 12 minutes ## TL;DR On July 21, 2026, OpenAI and Hugging Face published coordinated write-ups of the same ugly weekend. In OpenAI’s telling, a pre-release model with reduced cyber refusals — run inside a cyber-capability **evaluation** — discovered … Continue reading →

Securing the AI Coding Pipeline (Part 9)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…

The Founder’s Security Checklist: Shipping a Vibe-Coded MVP Without Getting Hacked (Part 8)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…

The AI Strategy Vacuum: Why “We Use ChatGPT” Isn’t a Plan

**Read Time:** 18 minutes ## TL;DR A CEO tells the board the company is “all in on AI.” Three floors down, here’s what that actually means: marketing is running a chatbot nobody in security has heard of, finance just pasted … Continue reading →

Prompt Engineering for Secure Code (Part 7)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…

Information Warfare Strategies (SRF-IWS): Offensive Operations Against a Papal Visit — Pope Leo XIV in Madrid 2026

> **Disclaimer:** Everything described here is pure imagination and any resemblance to reality is coincidental. This document is intended for security professionals to develop defensive countermeasures. The author is not responsible for the consequences of any action taken based on … Continue reading →

Scanning Vibe-Coded Apps: Why Traditional SAST/DAST Falls Short (part 6)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…

When Agents Fix Agents: How Hermes Patched OpenClaw After a Bad Update

**Read Time:** 7 minutes ## TL;DR I told OpenClaw to update itself. It did. Then the gateway refused to start because a config field had quietly changed shape between releases (`channels.discord.streaming` went from string to object). `openclaw doctor –fix` saw … Continue reading →

Authentication & Secrets: What AI Gets Wrong Every Time (Part 5)

> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026’s Worst…