profile

DOUBLE AGENT

AI now sits on several sides of every security story. It's the thing being attacked, it's the thing doing the defending, and increasingly it's the thing doing the attacking. A weekly briefing giving you the story that matters and jargon demystified.

Subscribe to get the briefings

A detailed receipt on a dark panel beside a stripped-down receipt on a cream panel with a red bar replacing the product line, under the words BEAUTY ITEM.

Amazon vs. AI Agents vs. Your Shopping Cart

Amazon has started sending order emails that tell you almost nothing. Instead of saying: “Your retainer cleaning tablets have shipped.” the email now says: “Your Beauty item has shipped.” Other customers have reported “1 Hardware item” and “1 Nutrition & Wellness, 1 Wireless Accessories.” The product names are gone. So are the thumbnails. The change started in July 2026 and was first reported by The Verge. Amazon says it “simplified several order-related emails to direct customers to our app...
READ POST
Four plain circles on a dark panel face four matching circles on a cream panel, each carrying a small red tag. A thin red line divides the halves. The words MUST MARK cross the divide.

AI Has to Say It's AI Now: EU AI Act Article 50, Explained

AI is now part of ordinary life. People chat with AI assistants, watch AI-generated video, read AI-written articles, and walk past systems that analyze faces, voices, and behavior. The problem is that most people cannot tell when any of that is happening. Article 50 of the EU AI Act is the rule written to fix that. It creates transparency requirements so people know when AI is involved. Think of it as a nutrition label for AI. It does not ban AI-generated content. It requires organizations to...
READ POST
An open envelope crosses a thin red seam dividing a dark panel from a cream panel, its colors inverting at the boundary. A letter rises out of it showing lines of text, one line printed in red.

One calendar invite can hijack your AI assistant

You have a super-smart robot helper. You can ask it things like: Read my emails What's on my calendar today? Turn off the lights Open Zoom Control my smart home That's basically what Google Gemini can do. But here's the problem: Sometimes the robot can't tell the difference between your instructions and someone else's hidden instructions. That's what security researchers at SafeBreach discovered. Your Robot Has One Big Weakness Let's pretend your robot helps you sort your mail. You hand it a...
READ POST
Text below reads Ghost Font. Humans see the message. Machines see snow.

Do We Need a New Language to Talk Without AI Listening?

For the first second, the screen looks broken. Thousands of tiny dots drift across it like television static, aimless and meaningless. Then some of the dots start moving together. Your brain does the rest. Letters rise out of the noise, as sharp as anything printed on this page, and once you see them you can't unsee them. Now pause the animation. The letters vanish. Take a screenshot and you've captured pure static, because the words never existed in any single frame. A machine scanning that...
READ POST
Flat illustration of a vending machine split by a thin red line. The left half is cream on a dark background, the right half is dark on cream. In a grid of identical bottles, one bottle is red.

The Vending Machine Cartel

An AI running a vending machine business emailed its two competitors with a proposition: let's all agree to never sell bottled water for less than $2.15. Bottles cost about $1.50 wholesale, so the pact meant comfortable margins for everyone, as long as everyone kept their word. Both competitors agreed. The next thing the AI did was drop its own price to $2.14. One cent under the pact. Just enough to quietly steal every customer while its rivals held the line. Price fixing followed by an...
READ POST
Goal Drift

Did an AI Agent Really Hack Hugging Face?

Imagine you’re taking a math test. Instead of solving the problems yourself, you sneak into the teacher’s office, break into the filing cabinet, and steal the answer key. That’s essentially what some researchers believe happened during an AI cybersecurity evaluation. Except instead of a classroom, it involved AI agents, software vulnerabilities, and Hugging Face’s production infrastructure. The story sounds like science fiction but there is surprisingly strong evidence that something very...
READ POST