TECH.
FOR.
HUMANS.
The AI Act Is Being Weakened Before It Starts
EDRi says the EU AI Omnibus would delay high-risk AI safeguards and reduce public transparency. That is not boring Brussels plumbing. It is where accountability disappears.
I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.
No fear-mongering. No affiliate tax. Just the plain-English version.
LATEST
74 articles and counting. Newest first.
AI Builders Are Production Servers Now
Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.
The Schema Was Not Supposed to Run Code
Six protobuf.js bugs are a useful warning for Node teams: parsers, schemas, and generated code are now part of your execution boundary. Treat them that way.
Court Orders Do Not Stop Spyware by Themselves
Meta says it disrupted NSO-linked WhatsApp phishing even after a court order barred NSO from targeting WhatsApp users. That is the point: spyware is an operational problem, not just a legal one.
AI Coding Agents Are Getting a Control Room
GitHub's Copilot app is a useful signpost: coding agents are moving from chat boxes into orchestration software, so the security model has to move too.
AI Bug Hunting Is Turning Vulnerability Triage Into a Firehose
Depthfirst says an AI security agent found 21 FFmpeg zero-days for about $1,000. Chrome just patched 429 bugs. The hard part is no longer only finding flaws. It is deciding what gets fixed first.
Face Recognition Should Not Ship Quietly
WIRED and EFF found unreleased face-recognition code in Meta's smart-glasses platform. The privacy problem is not only what shipped. It is what can be switched on later.
- criticalOracle Mitigates PeopleSoft Zero-Day Exploited by ShinyHuntersSecurityWeek / The Hacker News / OracleJun 12
- highOpenClaw Agent Attacks Show Hidden Inputs Can Become Tool CallsThe Hacker News / Imperva / VaronisJun 11
- mediumGreatXML BitLocker Bypass Claim Needs Careful Triage, Not PanicThe Hacker News / security researcher discussionJun 11
- highEDRi Warns EU AI Omnibus Would Delay Safeguards and Weaken TransparencyEuropean Digital Rights (EDRi)Jun 11