How security failures learned to sound reasonable

The most useful phrases in a modern security programme are the ones that cannot be argued with. “The platform gives us coverage.”, “We have visibility.”, “The tool supports MFA.” Each one is calm, professional, and technically defensible. Each one can also be doing something quietly different from what the room hears. …

May 3, 2026 · 4 min
A colossal cracked black monolithic slab

The Glasswing problem

On 7 April 2026, Anthropic announced two things at once. The first was a new frontier model called Claude Mythos Preview. The second was Project Glasswing, a coalition of twelve technology and finance companies that would receive controlled access to that model, with everyone else, including paying API customers, locke…

April 25, 2026 · 15 min

Threat modelling for zero-day vulnerabilities

Threat modelling for zero-day vulnerabilities is a peculiar exercise in preparing for the unknowable. These are not the comfortable, catalogue‑ready bugs that live in CVE databases. These are the ones nobody, least of all the vendor, has seen fit to admit exist. They arrive without warning, without a patch, and with pr…

August 3, 2025 · 7 min
An enormous, intricate tapestry hanging on a wall, with lots of loose threads dangling, a person on a ladder sewing them back in, lots of bright golden yellow, Renaissance-inspired realism, ornate patterns, dramatic chiaroscuro lighting

Tidying the loose ends before the whole thing unravels

In the spring of 2021, Dutch Institute for Vulnerability Disclosure (DIVD) researcher Wietse Boonstra quietly uncovered seven critical flaws in Kaseya’s widely used IT management software. DIVD warned the company within days, flagging more than 2,200 vulnerable systems across the globe. Weeks later, three flaws remaine…

August 3, 2025 · 4 min